Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox HIGH 7.8
CVE-2009-3987

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception me…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Db2 HIGH 7.5
CVE-2009-4333

The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st…

Patch available
Fix from $1,950 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4298

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within t…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4300

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, ev…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers t…

Patch available
Fix from $1,600 2009-12-16
Zen Cart MEDIUM 5.0
CVE-2009-4322

extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation p…

No fix yet
Fix from $1,600 2009-12-14
Adobe Air HIGH 7.1
CVE-2009-3951

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows re…

Fix: after 10.0.32.18
Fix from $1,950 2009-12-10
Pphlogger MEDIUM 5.0
CVE-2009-4254

PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_cssc…

Mitigation only
Fix from $1,600 2009-12-10
Ec Cube Ver2 MEDIUM 5.0
CVE-2009-4236

The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Commun…

Patch available
Fix from $1,600 2009-12-08
Cutenews MEDIUM 5.0
CVE-2009-4175

CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_dat…

No fix yet
Fix from $1,600 2009-12-02
Wp Cumulus MEDIUM 5.0
CVE-2009-4170EPSS 6%

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to …

No fix yet
Fix from $1,600 2009-12-02
Dotnetnuke MEDIUM 5.0
CVE-2009-4109

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need…

Mitigation only
Fix from $1,600 2009-11-29
Bugzilla MEDIUM 5.0
CVE-2009-3386

Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) D…

Patch available
Fix from $1,600 2009-11-20
Joomla\! MEDIUM 5.0
CVE-2009-3946

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct reques…

Fix: after 1.5.14
Fix from $1,600 2009-11-16
Asterisk MEDIUM 5.0
CVE-2009-3727

Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x b…

Patch available
Fix from $1,600 2009-11-10
Openjdk HIGH 7.5
CVE-2009-3881

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which …

Fix: after 1.6.0
Fix from $1,950 2009-11-09
Openjdk HIGH 7.5
CVE-2009-3882

Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknow…

Fix: after 1.6.0
Fix from $1,950 2009-11-09
Openjdk HIGH 7.5
CVE-2009-3883

Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Upda…

Fix: after 1.6.0
Fix from $1,950 2009-11-09
Runcms MEDIUM 5.0
CVE-2009-3815

RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to m…

No fix yet
Fix from $1,600 2009-10-27
Phpbms MEDIUM 5.0
CVE-2009-3756

phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in ad…

No fix yet
Fix from $1,600 2009-10-22
Navicopa Web Server MEDIUM 5.0
CVE-2009-3646EPSS 6%

InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DA…

No fix yet
Fix from $1,600 2009-10-09
Hubscript MEDIUM 5.0
CVE-2009-3600

HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo functio…

No fix yet
Fix from $1,600 2009-10-08
Xerver MEDIUM 5.0
CVE-2009-3544

Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the H…

No fix yet
Fix from $1,600 2009-10-05
Ace Web Application Firewall MEDIUM 5.0
CVE-2009-3457

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP requ…

Fix: after 6.0
Fix from $1,600 2009-09-29
I Load MEDIUM 5.0
CVE-2009-3452

WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigge…

Fix: after 2008.2.4.0
Fix from $1,600 2009-09-29
Uebimiau MEDIUM 5.0
CVE-2009-3199

Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…

No fix yet
Fix from $1,600 2009-09-15
Ubuntu Linux MEDIUM 5.0
CVE-2009-2797

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from…

Fix: 3.1 / 3.1.1+
Fix from $1,600 2009-09-10
Coppermine Photo Gallery MEDIUM 5.0
CVE-2008-7187

Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, whic…

Patch available
Fix from $1,600 2009-09-09
Eshop MEDIUM 5.0
CVE-2009-2266

OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other u…

Fix: after 3.0.4.1
Fix from $1,600 2009-09-09
Rails MEDIUM 5.0
CVE-2009-3086

A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature …

Patch available
Fix from $1,600 2009-09-08