Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,934 CVEs tagged with CWE-3061,100 Critical, 1,147 High, 635 Medium, 52 Low, 0 Unrated.

CVE-2014-4872

Published Oct 10, 2014

BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive cre…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-3055

Published Mar 22, 2012

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6827

Published Jun 8, 2009

The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1780

Published May 22, 2009

admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileg…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0213

Published Aug 6, 2004

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,926-2,934 of 2,934 CVEsPage 118 of 118