Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Arcserve D2d MEDIUM 5.0
CVE-2011-3011EPSS 72%

BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently…

No fix yet
Fix from $1,600 2011-08-15
WordPress MEDIUM 5.0
CVE-2011-3126

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

Patch available
Fix from $1,600 2011-08-10
WordPress MEDIUM 5.0
CVE-2011-3128

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive d…

Patch available
Fix from $1,600 2011-08-10
Bugzilla MEDIUM 5.0
CVE-2011-2380

Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.…

Patch available
Fix from $1,600 2011-08-09
Glpi MEDIUM 5.0
CVE-2011-2720

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obta…

Fix: after 0.80.1
Fix from $1,600 2011-08-05
Joomla\! MEDIUM 5.0
CVE-2011-2488

Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 1.5.22
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2889

templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger…

Fix: after 1.5.22
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2890

The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obt…

Fix: after 1.5.23
Fix from $1,600 2011-07-27
Joomla\! MEDIUM 5.0
CVE-2011-2891

Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals th…

No fix yet
Fix from $1,600 2011-07-27
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2759

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an o…

Mitigation only
Fix from $1,600 2011-07-17
Asterisk MEDIUM 5.0
CVE-2011-2536

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk…

Patch available
Fix from $1,600 2011-07-06
Linux Kernel MEDIUM 5.0
CVE-2011-1173

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain pote…

Fix: 2.6.39+
Fix from $1,600 2011-06-22
Smf MEDIUM 5.0
CVE-2011-1131

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation…

Fix: after 1.1.12
Fix from $1,600 2011-06-21
Rvs4000 MEDIUM 5.0
CVE-2011-1647

The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …

Mitigation only
Fix from $1,600 2011-05-31
Smarterstats MEDIUM 5.0
CVE-2011-2152

The SmarterTools SmarterStats 6.0 web server generates web pages containing external links in response to GET requests with query strings for (1) Cli…

Mitigation only
Fix from $1,600 2011-05-20
Smarterstats MEDIUM 5.0
CVE-2011-2153

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes i…

Mitigation only
Fix from $1,600 2011-05-20
Smarterstats MEDIUM 5.0
CVE-2011-2154

login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, wh…

Mitigation only
Fix from $1,600 2011-05-20
Smarterstats MEDIUM 5.0
CVE-2011-2156

The SmarterTools SmarterStats 6.0 web server allows remote attackers to obtain directory listings via a direct request for the (1) Admin/, (2) Admin/…

Mitigation only
Fix from $1,600 2011-05-20
Struts MEDIUM 5.0
CVE-2011-2088EPSS 6%

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati…

Patch available
Fix from $1,600 2011-05-13
Mediacast MEDIUM 5.0
CVE-2011-2076

MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by readi…

Fix: after 8
Fix from $1,600 2011-05-10
Mediacast MEDIUM 5.0
CVE-2011-2081

MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote atta…

Fix: after 8
Fix from $1,600 2011-05-10
Rational Build Forge MEDIUM 5.0
CVE-2011-1839

IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for…

Mitigation only
Fix from $1,600 2011-04-28
Network Automation MEDIUM 5.0
CVE-2011-1725

Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknow…

No fix yet
Fix from $1,600 2011-04-27
Network Satellite Server MEDIUM 6.4
CVE-2009-0788

Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecifie…

No fix yet
Fix from $1,600 2011-04-18
Kace K2000 Systems Deployment Appliance MEDIUM 5.0
CVE-2011-1672

The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitiv…

Fix: after 3.3.36822
Fix from $1,600 2011-04-10
Tine MEDIUM 5.0
CVE-2011-1666

Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (…

No fix yet
Fix from $1,600 2011-04-10
Enano Cms MEDIUM 5.0
CVE-2010-4781

index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive inform…

Fix: after 1.1.7
Fix from $1,600 2011-04-07
Portal MEDIUM 5.0
CVE-2011-1569

download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2…

No fix yet
Fix from $1,600 2011-04-05
Discovery\&dependency Mapping Inventory MEDIUM 5.0
CVE-2011-0890

HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configur…

Mitigation only
Fix from $1,600 2011-03-25
Iphone Os MEDIUM 5.0
CVE-2011-1418

The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4…

Fix: after 4.2
Fix from $1,600 2011-03-11