Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Performance Insight HIGH 7.8
CVE-2009-3097

Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as…

No fix yet
Fix from $1,950 2009-09-08
Docebo MEDIUM 5.0
CVE-2008-7154

Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.mod…

Fix: after 3.5.0.3
Fix from $1,600 2009-09-02
Phpbb MEDIUM 6.8
CVE-2008-7143

phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to …

Mitigation only
Fix from $1,600 2009-09-01
Intralearn MEDIUM 5.0
CVE-2008-7146

IntraLearn Software IntraLearn 2.1, and possibly other versions before 4.2.3, allows remote attackers to obtain sensitive information via a direct re…

Fix: after 4.2
Fix from $1,600 2009-09-01
Faq Manager Pro MEDIUM 5.0
CVE-2008-7063

Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a databa…

No fix yet
Fix from $1,600 2009-08-25
Accms HIGH 7.5
CVE-2008-7069

All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attacker…

Fix: after 0.0.2
Fix from $1,950 2009-08-25
Websphere Commerce Suite MEDIUM 5.0
CVE-2009-2956

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient acc…

Mitigation only
Fix from $1,600 2009-08-24
Phpadultsite Cms MEDIUM 5.0
CVE-2008-6981

index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter…

Mitigation only
Fix from $1,600 2009-08-19
Phpauction MEDIUM 5.0
CVE-2008-6999

phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php…

No fix yet
Fix from $1,600 2009-08-19
Safari HIGH 7.1
CVE-2009-2200

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-ass…

Fix: after 4.0.2
Fix from $1,950 2009-08-12
Mxcamarchive HIGH 7.5
CVE-2008-6955EPSS 6%

mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configurat…

No fix yet
Fix from $1,950 2009-08-12
Openjdk HIGH 7.8
CVE-2009-2475

Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vec…

Fix: after 6
Fix from $1,950 2009-08-10
Phone System MEDIUM 5.0
CVE-2008-6896

login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote attackers to gain sensitive information via unspecified ve…

Mitigation only
Fix from $1,600 2009-08-03
Visual C\+\+ MEDIUM 6.5
CVE-2009-2495EPSS 34%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Mitigation only
Fix from $1,600 2009-07-29
Aspthai Forums MEDIUM 5.0
CVE-2008-6872EPSS 6%

ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

No fix yet
Fix from $1,600 2009-07-23
Kervinet Forum MEDIUM 5.0
CVE-2009-2329

KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diag…

Fix: after 1.1
Fix from $1,600 2009-07-05
Cms Chainuk MEDIUM 5.0
CVE-2009-2332

CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent …

Fix: after 1.2
Fix from $1,600 2009-07-05
D100 HIGH 7.8
CVE-2009-2274

The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3…

Mitigation only
Fix from $1,950 2009-07-01
Stardict MEDIUM 5.0
CVE-2009-2260

stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obta…

Mitigation only
Fix from $1,600 2009-06-30
Video Surveillance 2500 Series Ip Camera MEDIUM 6.8
CVE-2009-2046

The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary file…

Fix: after 2.0
Fix from $1,600 2009-06-25
Pivot MEDIUM 5.0
CVE-2009-2134

pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the insta…

No fix yet
Fix from $1,600 2009-06-19
Elvinbts MEDIUM 5.0
CVE-2009-2130

Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct reque…

No fix yet
Fix from $1,600 2009-06-19
Skybluecanvas MEDIUM 6.8
CVE-2009-2115

admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which rev…

Mitigation only
Fix from $1,600 2009-06-18
Safari HIGH 7.1
CVE-2009-1703

WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari MEDIUM 5.0
CVE-2009-1706

The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstanc…

Fix: after 3.2.3
Fix from $1,600 2009-06-10
Safari HIGH 7.1
CVE-2009-1713

The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read …

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 7.1
CVE-2009-1718

WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dra…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Newsboard HIGH 7.8
CVE-2009-1949

import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the…

No fix yet
Fix from $1,950 2009-06-05
Websphere Application Server MEDIUM 5.0
CVE-2009-1898

The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an…

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03
Websphere Application Server MEDIUM 5.0
CVE-2009-1900

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, …

Fix: after 6.0.2.33
Fix from $1,600 2009-06-03