Vulnerabilities (CVE)

Filtered by CWE-264
Total 5476 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3605 1 Mcafee 1 Encrypted Usb Manager 2025-04-09 6.8 MEDIUM N/A
Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.
CVE-2007-5787 1 Phptoys 1 Micro Login System 2025-04-09 5.0 MEDIUM N/A
Micro Login System 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a password via a direct request for userpwd.txt.
CVE-2008-5898 1 Codeavalanche 1 Directory 2025-04-09 7.5 HIGH N/A
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CADirectory.mdb. NOTE: some of these details are obtained from third party information.
CVE-2009-2649 1 Freebsd 1 Freebsd 2025-04-09 4.7 MEDIUM N/A
The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value.
CVE-2008-4600 1 Steve Dawson 1 Pokermax Poker League Tournament Script 2025-04-09 7.5 HIGH N/A
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.
CVE-2009-4215 2 Microsoft, Pandasecurity 6 Windows 7, Windows Vista, Windows Xp and 3 more 2025-04-09 7.2 HIGH N/A
Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.
CVE-2009-2027 1 Apple 1 Safari 2025-04-09 7.2 HIGH N/A
The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.
CVE-2008-7056 1 Grayscalecms 1 Bandsite Cms 2025-04-09 5.0 MEDIUM N/A
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.
CVE-2008-7080 1 Phpclassifiedsscript 1 Php Classifieds Script 2025-04-09 5.0 MEDIUM N/A
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
CVE-2008-2724 1 Menalto 1 Gallery 2025-04-09 5.0 MEDIUM N/A
Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.
CVE-2010-0318 1 Freebsd 1 Freebsd 2025-04-09 6.9 MEDIUM N/A
The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.
CVE-2009-4331 1 Ibm 1 Db2 2025-04-09 7.2 HIGH N/A
The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.
CVE-2008-7010 1 Skalinks 1 Exchange Script 2025-04-09 10.0 HIGH N/A
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.
CVE-2009-2080 1 Mrcgiguy 1 The Ticket System 2025-04-09 7.5 HIGH N/A
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.
CVE-2008-3047 1 Typo3 1 Kb Unpack Extension 2025-04-09 7.5 HIGH N/A
Incomplete blacklist vulnerability in the KB Unpack (kb_unpack) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors.
CVE-2008-6963 1 Turnkeyforms 1 Text Link Sales 2025-04-09 7.5 HIGH N/A
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.
CVE-2008-4511 1 Todd Woolums 1 Asp News Management 2025-04-09 5.0 MEDIUM N/A
Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
CVE-2008-6929 1 Phpstore 1 Auto Classifieds 2025-04-09 6.5 MEDIUM N/A
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/.
CVE-2009-2854 1 Wordpress 1 Wordpress 2025-04-09 6.4 MEDIUM N/A
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.
CVE-2008-1095 1 Sun 2 Solaris, Sunos 2025-04-09 6.8 MEDIUM N/A
Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.