Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Blackberry Torch 9800 Firmware MEDIUM 5.0
CVE-2011-1416

The Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246 allows attackers to read the contents of memory locations via unknown vect…

Mitigation only
Fix from $1,600 2011-03-11
Chrome MEDIUM 5.0
CVE-2011-1190

The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors,…

Fix: 5.0 / 5.0.6+
Fix from $1,600 2011-03-11
Chrome MEDIUM 5.0
CVE-2011-1187

Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak…

Fix: 2.9 / 10.0.648.127+
Fix from $1,600 2011-03-11
Policy Manager MEDIUM 5.0
CVE-2011-1103

The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before …

Patch available
Fix from $1,600 2011-02-25
Telepresence System Software HIGH 10.0
CVE-2011-0376

The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain …

Mitigation only
Fix from $1,950 2011-02-25
Chrome MEDIUM 5.0
CVE-2011-0776

The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information ab…

Fix: 9.0.597.84+
Fix from $1,600 2011-02-04
Pivotx MEDIUM 5.0
CVE-2011-0774

PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.p…

Patch available
Fix from $1,600 2011-02-04
Pivotx MEDIUM 5.0
CVE-2011-0775

pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image paramete…

Mitigation only
Fix from $1,600 2011-02-04
Coldfusion MEDIUM 5.3
CVE-2011-0737

Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the i…

Fix: after 9.0.1
Fix from $1,600 2011-02-01
Coldfusion MEDIUM 5.3
CVE-2011-0736

Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive …

Fix: after 9.0.1
Fix from $1,600 2011-02-01
Websphere Portal MEDIUM 5.0
CVE-2011-0679

IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows rem…

No fix yet
Fix from $1,600 2011-01-28
Roomwizard Firmware MEDIUM 5.0
CVE-2010-0214

The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web fo…

No fix yet
Fix from $1,600 2011-01-12
Mono MEDIUM 5.0
CVE-2010-4225

Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.…

Mitigation only
Fix from $1,600 2011-01-11
Mantisbt MEDIUM 5.0
CVE-2010-4349EPSS 9%

admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which…

Fix: after 1.2.3
Fix from $1,600 2011-01-03
Mybb MEDIUM 5.0
CVE-2010-4625

MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows rem…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Habari MEDIUM 5.0
CVE-2010-4608

Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admi…

No fix yet
Fix from $1,600 2010-12-29
Html Edit Cms MEDIUM 5.0
CVE-2010-4611

Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_f…

No fix yet
Fix from $1,600 2010-12-29
Dojo Toolkit MEDIUM 5.0
CVE-2010-4600

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read…

Mitigation only
Fix from $1,600 2010-12-29
Insight Management Agents MEDIUM 5.0
CVE-2010-4112

HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure o…

Fix: after 8.5
Fix from $1,600 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4580

Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive in…

Fix: after 11.00
Fix from $1,600 2010-12-22
Icedtea MEDIUM 5.0
CVE-2010-3860

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which…

Fix: after 1.9.1
Fix from $1,600 2010-12-08
Websphere Commerce MEDIUM 5.0
CVE-2010-2639

IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving acc…

Mitigation only
Fix from $1,600 2010-12-06
Register Plus MEDIUM 5.0
CVE-2010-4403

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_wid…

Fix: after 3.5.1
Fix from $1,600 2010-12-06
Dynpg MEDIUM 5.0
CVE-2010-4401EPSS 6%

languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation pat…

Patch available
Fix from $1,600 2010-12-06
Siteengine MEDIUM 5.0
CVE-2008-7268

The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in misc.php.

No fix yet
Fix from $1,600 2010-12-01
Asa 5500 MEDIUM 5.0
CVE-2010-4354

The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series device…

Mitigation only
Fix from $1,600 2010-11-30
Spree MEDIUM 5.0
CVE-2010-3978

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating request…

Patch available
Fix from $1,600 2010-11-17
Bugzilla MEDIUM 5.0
CVE-2010-3764

The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, whi…

Patch available
Fix from $1,600 2010-11-05
Businessobjects MEDIUM 5.0
CVE-2010-3979

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid use…

No fix yet
Fix from $1,600 2010-10-18
Businessobjects MEDIUM 5.0
CVE-2010-3982

SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentia…

No fix yet
Fix from $1,600 2010-10-18