Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Openconnect MEDIUM 5.0
CVE-2010-3902

OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by…

Fix: after 2.25
Fix from $1,600 2010-10-14
Glibc MEDIUM 5.0
CVE-2010-3192

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow co…

Fix: 2.26+
Fix from $1,600 2010-10-14
Linux Kernel MEDIUM 5.5
CVE-2010-2538

Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive …

Fix: 2.6.35+
Fix from $1,600 2010-09-30
Linux Kernel HIGH 8.1
CVE-2010-2943EPSS 17%

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote a…

Fix: 2.6.35+
Fix from $1,950 2010-09-30
Ccagent MEDIUM 6.9
CVE-2010-3280

The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relie…

Fix: after 8.0
Fix from $1,600 2010-09-23
Linux Kernel MEDIUM 5.5
CVE-2010-3078

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member,…

Fix: after 2.6.35.4
Fix from $1,600 2010-09-21
Chrome MEDIUM 5.0
CVE-2010-3417

Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentiall…

Fix: 6.0.472.59+
Fix from $1,600 2010-09-16
Cfnetwork MEDIUM 5.0
CVE-2010-1800

CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a conn…

Patch available
Fix from $1,600 2010-08-25
Chrome MEDIUM 5.0
CVE-2010-3118

The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow r…

Fix: 5.0.375.127+
Fix from $1,600 2010-08-24
Bugzilla MEDIUM 5.0
CVE-2010-2758

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whethe…

Mitigation only
Fix from $1,600 2010-08-16
Web Server Plugin MEDIUM 5.0
CVE-2010-2989

nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the…

Mitigation only
Fix from $1,600 2010-08-10
Unified Wireless Network Solution Software HIGH 7.1
CVE-2010-2982

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to discover a group password via a series of SNMP requests,…

Mitigation only
Fix from $1,950 2010-08-10
HTTP Server MEDIUM 5.0
CVE-2010-2791EPSS 8%

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…

Mitigation only
Fix from $1,600 2010-08-05
Firefox MEDIUM 5.0
CVE-2010-2754

dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, an…

Fix: after 2.0.5
Fix from $1,600 2010-07-30
Lanai Core MEDIUM 5.0
CVE-2009-4961

Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.

No fix yet
Fix from $1,600 2010-07-28
Simpnews MEDIUM 5.0
CVE-2010-2859

news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the inst…

Fix: after 2.47.03
Fix from $1,600 2010-07-25
Alternet Csa Out MEDIUM 5.0
CVE-2009-4951

Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to ob…

Fix: after 0.3.0
Fix from $1,600 2010-07-22
Adpeeps MEDIUM 5.0
CVE-2009-4943

index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an invalid uid parameter, which…

Mitigation only
Fix from $1,600 2010-07-22
Litespeed Web Server MEDIUM 5.0
CVE-2010-2333EPSS 60%

LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a…

Patch available
Fix from $1,600 2010-06-18
Yamamah MEDIUM 5.0
CVE-2010-2336

index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the do…

Patch available
Fix from $1,600 2010-06-18
Websphere Application Server MEDIUM 5.0
CVE-2010-2323

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_creat…

Fix: after 7.0.0.10
Fix from $1,600 2010-06-18
HTTP Server MEDIUM 5.0
CVE-2010-2068EPSS 16%

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…

Patch available
Fix from $1,600 2010-06-18
Nginx MEDIUM 5.0
CVE-2010-2263EPSS 72%

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrar…

Fix: 0.7.66+
Fix from $1,600 2010-06-15
Virtualiq MEDIUM 5.0
CVE-2009-4844

ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2010-05-07
Webmathematica MEDIUM 5.0
CVE-2009-4812

Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the ins…

No fix yet
Fix from $1,600 2010-04-27
Windows 2000 MEDIUM 5.0
CVE-2010-0025EPSS 21%

The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, d…

Patch available
Fix from $1,600 2010-04-14
Workstation MEDIUM 5.0
CVE-2010-1138

The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMwa…

Patch available
Fix from $1,600 2010-04-12
Opera Browser MEDIUM 5.0
CVE-2010-1310

Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other…

Mitigation only
Fix from $1,600 2010-04-08
Chrome HIGH 10.0
CVE-2010-1230

Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Securit…

Fix: 4.1.249.1036+
Fix from $1,950 2010-04-01
Internet Explorer MEDIUM 6.5
CVE-2010-0488EPSS 29%

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas…

Patch available
Fix from $1,600 2010-03-31