Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Websense Email Security MEDIUM 5.0
CVE-2012-4605

The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScou…

Mitigation only
Fix from $1,600 2012-08-23
Websense Email Security MEDIUM 5.0
CVE-2009-5122

The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from t…

Fix: after 7.1
Fix from $1,600 2012-08-23
Enterprise Mobility Manager MEDIUM 5.0
CVE-2012-4591

About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, wh…

Fix: after 9.6
Fix from $1,600 2012-08-22
phpMyAdmin MEDIUM 5.0
CVE-2012-4219

show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals…

Patch available
Fix from $1,600 2012-08-21
Devotee MEDIUM 5.0
CVE-2012-2387

devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers…

Mitigation only
Fix from $1,600 2012-08-20
Rational Clearquest MEDIUM 5.0
CVE-2012-0744EPSS 8%

IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reque…

Mitigation only
Fix from $1,600 2012-08-17
Fortify Software Security Center MEDIUM 5.0
CVE-2012-3248

HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,600 2012-08-16
Shareyourcart MEDIUM 5.0
CVE-2012-4332

The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK.

No fix yet
Fix from $1,600 2012-08-14
Com Jnews MEDIUM 5.0
CVE-2012-4256

The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveal…

No fix yet
Fix from $1,600 2012-08-13
Yet Another Question \& Answer System MEDIUM 5.0
CVE-2012-4257

Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPS…

No fix yet
Fix from $1,600 2012-08-13
Mybb MEDIUM 5.0
CVE-2012-2327

MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the i…

Fix: after 1.6.6
Fix from $1,600 2012-08-13
Ushahidi Platform MEDIUM 5.0
CVE-2012-3474

The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensit…

Fix: after 2.4.1
Fix from $1,600 2012-08-12
Com Rsgallery2 MEDIUM 5.0
CVE-2012-4235

The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote at…

Fix: after 3.1.0
Fix from $1,600 2012-08-10
Nhn Japan Naver Line MEDIUM 5.0
CVE-2012-4005

The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sens…

Fix: after 2.5
Fix from $1,600 2012-08-07
Wide Area Application Services MEDIUM 5.0
CVE-2012-1348

Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which…

Mitigation only
Fix from $1,600 2012-08-06
Chrome MEDIUM 5.0
CVE-2012-2854

Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain poten…

Fix: after 21.0.1180.56
Fix from $1,600 2012-08-06
Toolbar MEDIUM 5.8
CVE-2012-2647

Yahoo! Toolbar 1.0.0.5 and earlier for Chrome and Safari allows remote attackers to modify the configured search URL, and intercept search terms, via…

Fix: after 1.0.0.5
Fix from $1,600 2012-07-31
Airdroid MEDIUM 5.0
CVE-2012-3886

AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attackers to o…

No fix yet
Fix from $1,600 2012-07-26
Rpx MEDIUM 5.0
CVE-2012-2296

The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data from Engage …

Patch available
Fix from $1,600 2012-07-25
Sitedoc MEDIUM 5.0
CVE-2012-2302

Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote a…

Patch available
Fix from $1,600 2012-07-25
Sleipnir Mobile MEDIUM 5.0
CVE-2012-2646

The Sleipnir Mobile application before 2.1.0 and Sleipnir Mobile Black Edition application before 2.1.0 for Android do not properly implement the Web…

Fix: 2.1.0+
Fix from $1,600 2012-07-25
Db2 MEDIUM 5.0
CVE-2012-2196

IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) …

Mitigation only
Fix from $1,600 2012-07-25
Moodle MEDIUM 5.0
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h…

Mitigation only
Fix from $1,600 2012-07-23
Viewvc MEDIUM 5.0
CVE-2012-3357

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from …

Fix: after 1.1.14
Fix from $1,600 2012-07-22
Moodle MEDIUM 5.0
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and…

Mitigation only
Fix from $1,600 2012-07-21
Firefox MEDIUM 5.0
CVE-2012-1960

The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and S…

Fix: after 2.10
Fix from $1,600 2012-07-18
Moodle MEDIUM 5.0
CVE-2011-4279

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4283

Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4284

Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context …

Mitigation only
Fix from $1,600 2012-07-16
Tikiwiki Cms\/groupware MEDIUM 5.0
CVE-2012-3996

TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php…

Fix: after 8.2
Fix from $1,600 2012-07-12