Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mac Os X Server MEDIUM 5.0
CVE-2010-0523

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2010-03-30
Firefox MEDIUM 5.8
CVE-2010-1125

The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to sen…

Fix: after 2.0.4
Fix from $1,600 2010-03-26
Webkit MEDIUM 5.8
CVE-2010-1126

The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intende…

Mitigation only
Fix from $1,600 2010-03-26
Ch Lightem MEDIUM 5.0
CVE-2010-1007

Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensit…

Fix: after 1.0.34
Fix from $1,600 2010-03-19
Digital Media Manager HIGH 7.1
CVE-2010-0572

Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related…

Fix: after 5.1
Fix from $1,950 2010-03-05
Moinmoin MEDIUM 5.0
CVE-2010-0667

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable…

Mitigation only
Fix from $1,600 2010-02-26
Com Jquarks MEDIUM 5.0
CVE-2010-0670

Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path fo…

Fix: after 0.2.3
Fix from $1,600 2010-02-22
Chrome MEDIUM 5.0
CVE-2010-0663

The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Chrome MEDIUM 5.0
CVE-2010-0660

Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirect…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Collaboration Server MEDIUM 5.0
CVE-2010-0642EPSS 8%

Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extensio…

No fix yet
Fix from $1,600 2010-02-17
Websphere Application Server MEDIUM 5.0
CVE-2010-0563

The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configur…

Patch available
Fix from $1,600 2010-02-08
Workcentre 5632 MEDIUM 5.0
CVE-2010-0548

Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow …

Patch available
Fix from $1,600 2010-02-04
Workcentre 6400 Net Controller MEDIUM 5.0
CVE-2010-0549

Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Con…

Patch available
Fix from $1,600 2010-02-04
Geo\+\+ Gncaster MEDIUM 5.0
CVE-2010-0551

HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a …

Fix: after 1.4.0.7
Fix from $1,600 2010-02-04
Imp MEDIUM 5.0
CVE-2010-0463

Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it …

Fix: after 4.3.6
Fix from $1,600 2010-01-29
Webmail MEDIUM 5.0
CVE-2010-0464

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it …

Fix: after 0.3.1
Fix from $1,600 2010-01-29
Seamonkey MEDIUM 5.0
CVE-2009-4629

Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or A…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.0
CVE-2009-4630

Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML d…

Mitigation only
Fix from $1,600 2010-01-29
Viewvc MEDIUM 5.0
CVE-2010-0004

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private…

Mitigation only
Fix from $1,600 2010-01-29
Linux Kernel MEDIUM 5.4
CVE-2010-0003

The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, all…

Fix: 2.6.32.4+
Fix from $1,600 2010-01-26
Tor MEDIUM 5.0
CVE-2010-0383

Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man…

Mitigation only
Fix from $1,600 2010-01-25
Tor MEDIUM 5.0
CVE-2010-0385

Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2010-01-25
Jetty MEDIUM 5.0
CVE-2009-4609

The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via …

No fix yet
Fix from $1,600 2010-01-13
Navicopa Web Server MEDIUM 5.0
CVE-2009-4529

InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space ch…

Fix: after 3.0.1.2
Fix from $1,600 2009-12-31
Mongoose MEDIUM 5.0
CVE-2009-4530

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.

Fix: after 2.8
Fix from $1,600 2009-12-31
Httpdx MEDIUM 5.0
CVE-2009-4531EPSS 7%

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

Fix: after 1.4.4
Fix from $1,600 2009-12-31
Webform MEDIUM 5.0
CVE-2009-4533

The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholder…

Fix: after 6.x-2.7
Fix from $1,600 2009-12-31
Mongoose MEDIUM 5.0
CVE-2009-4535EPSS 7%

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.

Fix: after 2.8.0
Fix from $1,600 2009-12-31
Deluxebb MEDIUM 5.0
CVE-2009-4466

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in…

No fix yet
Fix from $1,600 2009-12-30
Rational Clearcase MEDIUM 5.0
CVE-2009-4357

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might al…

Fix: after 7.1
Fix from $1,600 2009-12-18