Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Groupwise MEDIUM 5.0
CVE-2009-0274

Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2009-02-03
Websphere Application Server HIGH 7.8
CVE-2009-0391

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

No fix yet
Fix from $1,950 2009-02-02
Java System Access Manager MEDIUM 5.0
CVE-2009-0348EPSS 8%

The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt dep…

Patch available
Fix from $1,600 2009-01-29
Java System Application Server MEDIUM 5.0
CVE-2009-0278

Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2)…

Patch available
Fix from $1,600 2009-01-27
Mini Pub MEDIUM 5.0
CVE-2008-5936

front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName param…

Fix: after 0.3
Fix from $1,600 2009-01-22
Safari HIGH 7.1
CVE-2009-0123

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vector…

No fix yet
Fix from $1,950 2009-01-15
Internet Information Services HIGH 7.5
CVE-2003-1567EPSS 25%

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the res…

No fix yet
Fix from $1,950 2009-01-15
Asterisk Business Edition MEDIUM 5.0
CVE-2009-0041

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7…

Fix: after 1.6.0.3
Fix from $1,600 2009-01-14
Bea Product Suite MEDIUM 6.8
CVE-2008-5461

Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remot…

Mitigation only
Fix from $1,600 2009-01-14
Vpn 1 MEDIUM 5.0
CVE-2008-5849

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresse…

No fix yet
Fix from $1,600 2009-01-06
Windows Live Messenger MEDIUM 5.0
CVE-2008-5828EPSS 14%

Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers …

Fix: after 8.5.1
Fix from $1,600 2009-01-02
Opera Browser HIGH 7.8
CVE-2008-5683

Unspecified vulnerability in Opera before 9.63 allows remote attackers to "reveal random data" via unknown vectors.

Fix: after 9.62
Fix from $1,950 2008-12-19
Firefox MEDIUM 6.0
CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Control Center HIGH 7.8
CVE-2008-5420

The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which …

Fix: after 6.0
Fix from $1,950 2008-12-10
Windows Media Player HIGH 10.0
CVE-2008-3010EPSS 15%

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP ad…

Mitigation only
Fix from $1,950 2008-12-10
Websphere Application Server MEDIUM 5.0
CVE-2008-5413

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive in…

Fix: after 7.0
Fix from $1,600 2008-12-10
Jdk MEDIUM 5.0
CVE-2008-5341

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and ea…

Fix: after 6
Fix from $1,600 2008-12-05
Jdk MEDIUM 5.0
CVE-2008-5342

Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0…

Fix: after 6
Fix from $1,600 2008-12-05
Jre HIGH 7.1
CVE-2008-5346

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK …

Patch available
Fix from $1,950 2008-12-05
Jdk MEDIUM 5.0
CVE-2008-5350

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and S…

Fix: after 6
Fix from $1,600 2008-12-05
Wysi Wiki Wyg HIGH 7.8
CVE-2008-5322

Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo functio…

No fix yet
Fix from $1,950 2008-12-03
Samba HIGH 8.5
CVE-2008-4314

smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) tra…

Patch available
Fix from $1,950 2008-12-01
Iprint MEDIUM 5.0
CVE-2008-2432

Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers…

Fix: after 5.04
Fix from $1,600 2008-11-26
Windows MEDIUM 5.0
CVE-2008-5112EPSS 18%

The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending…

No fix yet
Fix from $1,600 2008-11-17
File List Extension MEDIUM 5.0
CVE-2008-5096

Unspecified vulnerability in the TYPO3 File List (file_list) extension 0.2.1 and earlier allows remote attackers to obtain sensitive information via …

Fix: after 0.2.1
Fix from $1,600 2008-11-14
Firefox MEDIUM 5.0
CVE-2008-5012

Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when proc…

Fix: after 2.0.0.17
Fix from $1,600 2008-11-13
Lotus Connections MEDIUM 5.0
CVE-2008-4808

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is u…

Fix: after 2.0
Fix from $1,600 2008-10-31
Opera HIGH 9.3
CVE-2008-4695EPSS 6%

Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cac…

Fix: after 9.60
Fix from $1,950 2008-10-23
Post Comment HIGH 7.5
CVE-2008-4721

PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie …

No fix yet
Fix from $1,950 2008-10-23
Mantis MEDIUM 5.0
CVE-2008-4688EPSS 12%

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, …

Fix: after 1.1.3
Fix from $1,600 2008-10-22