Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Freepbx MEDIUM 5.0
CVE-2009-1803

FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whe…

Patch available
Fix from $1,600 2009-05-28
Ocs Inventory Ng MEDIUM 5.0
CVE-2009-1769

The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whe…

Mitigation only
Fix from $1,600 2009-05-22
Wvc54gca MEDIUM 5.0
CVE-2009-1555

The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 sends configuration data in response to a Setup Wizard remote-mana…

No fix yet
Fix from $1,600 2009-05-06
Memcached MEDIUM 5.0
CVE-2009-1255

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats…

Fix: after 1.2.0
Fix from $1,600 2009-04-30
Libdbd Pg Perl MEDIUM 5.0
CVE-2009-1341

Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-depend…

Fix: after 1.4.9
Fix from $1,600 2009-04-30
Memcached MEDIUM 5.0
CVE-2009-1494

The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attack…

Patch available
Fix from $1,600 2009-04-30
Chrome HIGH 7.8
CVE-2009-1412

Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows re…

Fix: after 1.0.154.53
Fix from $1,950 2009-04-24
Crysis HIGH 7.8
CVE-2008-6737

Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet with…

Fix: after 1.21
Fix from $1,950 2009-04-21
Teaming MEDIUM 5.0
CVE-2009-1293

The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the us…

Patch available
Fix from $1,600 2009-04-16
Procurve Manager MEDIUM 5.0
CVE-2007-4514

Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information…

Fix: after 2.3
Fix from $1,600 2009-04-15
Db2 MEDIUM 5.0
CVE-2009-1239

IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OU…

Fix: after 9.1
Fix from $1,600 2009-04-03
Lightneasy MEDIUM 5.0
CVE-2008-6537EPSS 6%

LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setu…

No fix yet
Fix from $1,600 2009-03-30
Cisco Ios HIGH 9.0
CVE-2009-0628

Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device …

Mitigation only
Fix from $1,950 2009-03-27
Openterracotta HIGH 7.8
CVE-2008-6521

index.php in Terracotta (aka OpenTerracotta) 0.6.1 allows remote attackers to obtain sensitive information via an invalid File parameter, which revea…

Mitigation only
Fix from $1,950 2009-03-25
Java System Identity Manager MEDIUM 5.0
CVE-2009-1076

Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on w…

Patch available
Fix from $1,600 2009-03-25
Websphere Application Server HIGH 7.5
CVE-2009-0508

The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.…

Patch available
Fix from $1,950 2009-03-16
Enhanced Support Facility MEDIUM 5.0
CVE-2009-0867

The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via …

Mitigation only
Fix from $1,600 2009-03-10
Celerbb MEDIUM 5.0
CVE-2009-0852

showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.

No fix yet
Fix from $1,600 2009-03-09
Social Site Generator MEDIUM 5.0
CVE-2008-6420

Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.ph…

No fix yet
Fix from $1,600 2009-03-06
Firefox HIGH 7.1
CVE-2009-0776

nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-or…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
TYPO3 MEDIUM 5.0
CVE-2009-0815EPSS 42%

The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks…

Patch available
Fix from $1,600 2009-03-05
Quick Tree View .net MEDIUM 5.0
CVE-2008-6387

Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …

No fix yet
Fix from $1,600 2009-03-02
Simplefilebrowser MEDIUM 5.0
CVE-2008-6342

Unspecified vulnerability in the TYPO3 Simple File Browser (simplefilebrowser) extension 1.0.2 and earlier allows remote attackers to obtain sensitiv…

Fix: after 1.0.2
Fix from $1,600 2009-02-27
Rakhisoftware Shopping Cart HIGH 7.8
CVE-2008-6279

RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, wh…

No fix yet
Fix from $1,950 2009-02-25
Phpfootball MEDIUM 5.0
CVE-2009-0711

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable pa…

No fix yet
Fix from $1,600 2009-02-23
Ravennuke MEDIUM 5.0
CVE-2009-0678

images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not corres…

No fix yet
Fix from $1,600 2009-02-22
Cmme MEDIUM 5.0
CVE-2008-6159

Content Management Made Easy (CMME) 1.19 allows remote attackers to obtain system information via a direct request to info.php, which invokes the php…

No fix yet
Fix from $1,600 2009-02-18
Online Grades MEDIUM 5.0
CVE-2009-0453

Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

No fix yet
Fix from $1,600 2009-02-10
Openview Network Node Manager HIGH 7.8
CVE-2008-4560

HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to t…

Patch available
Fix from $1,950 2009-02-08
Controllogix 1756 Enbt\/a Ethernet\/ Ip Bridge MEDIUM 5.0
CVE-2009-0474EPSS 6%

The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page …

Mitigation only
Fix from $1,600 2009-02-06