Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Seditio MEDIUM 5.0
CVE-2012-5916

Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2…

No fix yet
Fix from $1,600 2012-11-17
Sr Feuser Register MEDIUM 5.0
CVE-2012-5890

The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via …

Fix: after 2.6.1
Fix from $1,600 2012-11-17
Monaca Debugger MEDIUM 5.0
CVE-2012-5172

The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information …

Fix: after 1.4.1
Fix from $1,600 2012-11-16
Bugzilla MEDIUM 5.0
CVE-2012-4197

Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x…

Patch available
Fix from $1,600 2012-11-16
Bugzilla MEDIUM 5.0
CVE-2012-5884

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches…

Mitigation only
Fix from $1,600 2012-11-16
.net Framework MEDIUM 5.0
CVE-2012-1896EPSS 24%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-11-14
Ftp Service MEDIUM 5.0
CVE-2012-2532EPSS 42%

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which a…

Mitigation only
Fix from $1,600 2012-11-14
Eoscada MEDIUM 5.0
CVE-2012-1812

eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP por…

Fix: after 11.0.19.1
Fix from $1,600 2012-11-13
Iphone Os MEDIUM 5.0
CVE-2012-3749

The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which mak…

Fix: after 6.0
Fix from $1,600 2012-11-03
Libsocialweb MEDIUM 5.8
CVE-2012-4511

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote atta…

Fix: after 0.25.20
Fix from $1,600 2012-10-22
Libsocialweb MEDIUM 5.8
CVE-2011-4129

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twit…

Fix: after 0.25.19
Fix from $1,600 2012-10-22
Rational Business Developer MEDIUM 5.0
CVE-2012-3319

IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web serv…

Fix: after 8.0.1.3
Fix from $1,600 2012-10-01
Vino MEDIUM 5.0
CVE-2012-4429

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

Fix: after 3.4.2
Fix from $1,600 2012-10-01
Condor MEDIUM 5.8
CVE-2012-3493

The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obt…

Mitigation only
Fix from $1,600 2012-09-28
Chrome MEDIUM 5.0
CVE-2012-2891

The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via u…

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Iphone Os MEDIUM 5.0
CVE-2012-3724

CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information b…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Moodle MEDIUM 5.0
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attack…

Patch available
Fix from $1,600 2012-09-19
Moodle MEDIUM 5.0
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files,…

Patch available
Fix from $1,600 2012-09-19
Anyconnect Secure Mobility Client MEDIUM 5.0
CVE-2012-3094

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.5…

Mitigation only
Fix from $1,600 2012-09-16
Mediawiki MEDIUM 5.0
CVE-2012-1579

The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which …

No fix yet
Fix from $1,600 2012-09-09
Joomla\! MEDIUM 5.0
CVE-2012-0837

Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."

Patch available
Fix from $1,600 2012-09-06
TYPO3 MEDIUM 5.0
CVE-2012-1607

The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attacker…

Mitigation only
Fix from $1,600 2012-09-04
Coppermine Photo Gallery MEDIUM 5.0
CVE-2012-1614EPSS 9%

Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…

Fix: after 1.5.18
Fix from $1,600 2012-09-04
Firefox MEDIUM 5.0
CVE-2012-3972

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, T…

Fix: 10.0.7 / 15.0+
Fix from $1,600 2012-08-29
Performance Co Pilot MEDIUM 5.0
CVE-2012-3419

Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pi…

Fix: after 3.6.4
Fix from $1,600 2012-08-27
Sgos MEDIUM 5.0
CVE-2011-5126

Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers…

Mitigation only
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5188

SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.p…

Patch available
Fix from $1,600 2012-08-26
Pluxml MEDIUM 5.0
CVE-2012-4674

PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.

Fix: after 5.1.5
Fix from $1,600 2012-08-26
Tor MEDIUM 5.0
CVE-2012-3519

routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow re…

Fix: after 0.2.2.37
Fix from $1,600 2012-08-26
Websense Email Security MEDIUM 5.0
CVE-2012-4605

The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScou…

Mitigation only
Fix from $1,600 2012-08-23