Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jdk MEDIUM 5.0
CVE-2008-3114

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.…

Fix: after 6
Fix from $1,600 2008-07-09
Mybloggie MEDIUM 5.3
CVE-2007-3650

myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through i…

No fix yet
Fix from $1,600 2008-07-09
Faname MEDIUM 5.3
CVE-2007-3651

class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence …

No fix yet
Fix from $1,600 2008-07-09
Opera Browser HIGH 7.8
CVE-2008-3078

Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized…

Fix: after 9.50
Fix from $1,950 2008-07-09
Data Engine MEDIUM 5.0
CVE-2008-0085EPSS 11%

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE…

Patch available
Fix from $1,600 2008-07-08
Firefox MEDIUM 5.0
CVE-2008-2807

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote att…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Dam Frontend Extension MEDIUM 5.0
CVE-2008-3040

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive inform…

Fix: after 0.1.0
Fix from $1,600 2008-07-07
Pdf Generator 2 Extension MEDIUM 5.0
CVE-2008-3049

The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

Fix: after 0.5.0
Fix from $1,600 2008-07-07
Relative Real Estate Systems MEDIUM 5.0
CVE-2008-2881

Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain se…

Fix: after 3.0
Fix from $1,600 2008-06-26
Site Composer MEDIUM 5.0
CVE-2008-2864

eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2…

Fix: after 2.6
Fix from $1,600 2008-06-25
Otomigenx HIGH 7.5
CVE-2008-2782

Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) …

No fix yet
Fix from $1,950 2008-06-19
Gallery MEDIUM 5.0
CVE-2008-2721

Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by att…

Fix: after 2.2.4
Fix from $1,600 2008-06-16
Gallery MEDIUM 5.0
CVE-2008-2723

embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address…

Fix: after 2.2.4
Fix from $1,600 2008-06-16
Opera Browser MEDIUM 5.0
CVE-2008-2715

Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as pat…

Fix: after 9.50
Fix from $1,600 2008-06-16
Realm Cms MEDIUM 5.0
CVE-2008-2681

Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database…

Fix: after 2.3
Fix from $1,600 2008-06-12
Mac Os X MEDIUM 5.0
CVE-2008-1579

Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message pr…

Patch available
Fix from $1,600 2008-06-02
Java System Application Server MEDIUM 5.0
CVE-2008-2120

Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update…

Fix: after 7.0
Fix from $1,600 2008-05-09
Authentication Agent MEDIUM 5.8
CVE-2008-2027

Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such…

Mitigation only
Fix from $1,600 2008-04-30
Network Admission Control HIGH 10.0
CVE-2008-1155

Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to ob…

Fix: after 4.1.1
Fix from $1,950 2008-04-16
Chartdirector MEDIUM 5.0
CVE-2008-1782

phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.

No fix yet
Fix from $1,600 2008-04-15
Ezradius HIGH 7.5
CVE-2008-1752

ezRADIUS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials vi…

Mitigation only
Fix from $1,950 2008-04-11
Burning Board MEDIUM 5.0
CVE-2008-1717

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) f…

Mitigation only
Fix from $1,600 2008-04-09
Firebox Pptp Vpn MEDIUM 5.0
CVE-2008-1618

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes dependi…

Patch available
Fix from $1,600 2008-04-07
Php Nuke Platinum MEDIUM 5.0
CVE-2008-1680

PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals se…

No fix yet
Fix from $1,600 2008-04-04
Bolinos MEDIUM 5.0
CVE-2008-1557

BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, whic…

No fix yet
Fix from $1,600 2008-03-31
Cisco Ios MEDIUM 5.1
CVE-2008-1156

Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attack…

Patch available
Fix from $1,600 2008-03-27
Prestige 660 MEDIUM 5.0
CVE-2008-1523

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to o…

Mitigation only
Fix from $1,600 2008-03-26
Peel MEDIUM 5.0
CVE-2008-1506

PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpi…

Fix: after 3.0
Fix from $1,600 2008-03-25
Mac Os X MEDIUM 6.8
CVE-2008-0052

CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0050

CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.

Patch available
Fix from $1,600 2008-03-18