Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Db2 MEDIUM 5.0
CVE-2008-4693

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attacker…

Fix: after 9.5
Fix from $1,600 2008-10-22
Hisa Cart MEDIUM 5.0
CVE-2008-4635

Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive u…

Fix: after 1.29
Fix from $1,600 2008-10-21
Systems Insight Manager MEDIUM 5.0
CVE-2008-4412

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive informa…

Fix: after 5.2
Fix from $1,600 2008-10-17
Mail MEDIUM 5.0
CVE-2008-4491

Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s…

Mitigation only
Fix from $1,600 2008-10-08
V Webmail MEDIUM 5.0
CVE-2008-3060

V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) …

Mitigation only
Fix from $1,600 2008-10-08
Debian Linux HIGH 7.5
CVE-2008-4359

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w…

Fix: 1.4.20+
Fix from $1,950 2008-10-03
Debian Linux HIGH 7.5
CVE-2008-4360

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam…

Fix: 1.4.20+
Fix from $1,950 2008-10-03
Opera Browser MEDIUM 5.0
CVE-2008-4199

Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determin…

Fix: after 9.51
Fix from $1,600 2008-09-27
Firefox MEDIUM 5.0
CVE-2008-4069

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obt…

Fix: after 2.0.0.16
Fix from $1,600 2008-09-24
Dolphin MEDIUM 5.0
CVE-2008-4207

Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive informat…

No fix yet
Fix from $1,600 2008-09-24
Nooms MEDIUM 5.0
CVE-2008-4180

Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbu…

No fix yet
Fix from $1,600 2008-09-23
Integramod MEDIUM 5.0
CVE-2008-4183

IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup…

No fix yet
Fix from $1,600 2008-09-23
Oscommerce MEDIUM 5.0
CVE-2008-4170

create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in…

Mitigation only
Fix from $1,600 2008-09-22
Phpbb MEDIUM 5.0
CVE-2008-4125

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially s…

Mitigation only
Fix from $1,600 2008-09-18
Talkback MEDIUM 5.0
CVE-2008-4115

TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.

No fix yet
Fix from $1,600 2008-09-16
Enterprise Ipa MEDIUM 5.0
CVE-2008-3274

The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, w…

Fix: after 1.1.0
Fix from $1,600 2008-09-12
Clamav HIGH 10.0
CVE-2008-3914

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path…

Fix: after 0.93.3
Fix from $1,950 2008-09-11
Adaptive Security Appliance 5500 HIGH 7.1
CVE-2008-2736

Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clie…

Mitigation only
Fix from $1,950 2008-09-04
Virtualcenter MEDIUM 5.0
CVE-2008-3514

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which a…

Fix: after 2.0.2
Fix from $1,600 2008-08-13
Windows Messenger HIGH 10.0
CVE-2008-0082EPSS 34%

An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to cont…

Mitigation only
Fix from $1,950 2008-08-13
Windows Nt HIGH 7.8
CVE-2008-2246EPSS 32%

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Se…

Patch available
Fix from $1,950 2008-08-13
Rational Clearquest MEDIUM 5.0
CVE-2008-3550

The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co…

Mitigation only
Fix from $1,600 2008-08-08
Vtiger Crm MEDIUM 5.0
CVE-2008-3458

Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail …

Fix: after 5.0.3
Fix from $1,600 2008-08-04
Jobbex Jobsite MEDIUM 6.8
CVE-2008-3339

search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path…

Patch available
Fix from $1,600 2008-07-28
Bilboblog MEDIUM 5.0
CVE-2008-3304EPSS 6%

BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct requ…

No fix yet
Fix from $1,600 2008-07-25
Empire Server MEDIUM 5.0
CVE-2008-3168

The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.

Fix: after 4.3.11
Fix from $1,600 2008-07-14
Safari MEDIUM 5.0
CVE-2008-3171

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive …

Mitigation only
Fix from $1,600 2008-07-14
Xcode MEDIUM 5.0
CVE-2008-2318

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remo…

Fix: after 3.0
Fix from $1,600 2008-07-14
Wireshark MEDIUM 5.0
CVE-2008-3138

The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (app…

Mitigation only
Fix from $1,600 2008-07-10
Wireshark MEDIUM 5.0
CVE-2008-3139

The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown ve…

Mitigation only
Fix from $1,600 2008-07-10