Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mediawiki MEDIUM 5.0
CVE-2008-1318

Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback param…

Patch available
Fix from $1,600 2008-03-13
Rational Clearquest MEDIUM 5.0
CVE-2008-1288

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

Patch available
Fix from $1,600 2008-03-11
Lighttpd MEDIUM 5.0
CVE-2008-1270EPSS 12%

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitra…

Fix: after 1.4.18
Fix from $1,600 2008-03-10
Speedport W500 Dsl Router HIGH 10.0
CVE-2008-1252

b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading t…

No fix yet
Fix from $1,950 2008-03-10
Secure Access 2000 MEDIUM 5.0
CVE-2008-1181

Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.c…

Mitigation only
Fix from $1,600 2008-03-06
Flyspray MEDIUM 5.0
CVE-2008-1166

Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate…

Mitigation only
Fix from $1,600 2008-03-05
Lighttpd MEDIUM 5.0
CVE-2008-1111

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers…

Mitigation only
Fix from $1,600 2008-03-04
Fs4104 Aw Device MEDIUM 5.0
CVE-2007-6702

goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows …

No fix yet
Fix from $1,600 2008-03-04
Interneserviceslosungen MEDIUM 5.0
CVE-2008-1135

OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed log…

No fix yet
Fix from $1,600 2008-03-04
Vocera Communications Badge HIGH 7.8
CVE-2008-1113

Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which al…

Mitigation only
Fix from $1,950 2008-03-03
Double Take MEDIUM 5.0
CVE-2008-0978

Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain s…

No fix yet
Fix from $1,600 2008-02-25
Weblogic Server HIGH 7.1
CVE-2008-0901

BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout …

Patch available
Fix from $1,950 2008-02-22
Aqualogic Interaction HIGH 7.8
CVE-2008-0904

Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remo…

Patch available
Fix from $1,950 2008-02-22
Weblogic Server MEDIUM 5.0
CVE-2008-0863

BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain se…

Patch available
Fix from $1,600 2008-02-21
Cacti MEDIUM 5.0
CVE-2008-0784

graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id paramete…

Patch available
Fix from $1,600 2008-02-14
Candypress Store MEDIUM 5.0
CVE-2008-0736

admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a ce…

No fix yet
Fix from $1,600 2008-02-13
Mac Os X MEDIUM 5.0
CVE-2008-0041

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determ…

Patch available
Fix from $1,600 2008-02-12
Managed Workplace Service Center MEDIUM 5.0
CVE-2008-0636

Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct re…

No fix yet
Fix from $1,600 2008-02-12
Firefox HIGH 9.3
CVE-2008-0420

modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not pr…

Fix: after 2.0.0.11
Fix from $1,950 2008-02-12
Tomcat MEDIUM 5.0
CVE-2007-5333EPSS 63%

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…

Fix: after 6.0.14
Fix from $1,600 2008-02-12
Acrobat HIGH 8.8
CVE-2008-0655 KEVEPSS 37%

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

Fix: 8.1.2+
Fix from $1,950 2008-02-07
Supportsuite MEDIUM 5.0
CVE-2008-0395

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints…

Mitigation only
Fix from $1,600 2008-01-23
Firefox MEDIUM 5.0
CVE-2008-0367

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authen…

Fix: after 2.0.0.11
Fix from $1,600 2008-01-19
Xserver MEDIUM 5.0
CVE-2007-5958EPSS 5%

X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X progra…

Fix: after 1.4
Fix from $1,600 2008-01-18
Photokorn MEDIUM 5.0
CVE-2008-0297

PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its ou…

No fix yet
Fix from $1,600 2008-01-16
Phpwebquest MEDIUM 5.0
CVE-2008-0249

PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the crede…

No fix yet
Fix from $1,600 2008-01-12
WordPress MEDIUM 5.0
CVE-2008-0191

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…

Mitigation only
Fix from $1,600 2008-01-10
WordPress MEDIUM 5.0
CVE-2008-0195

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts …

Fix: after 2.0.11
Fix from $1,600 2008-01-10
Helpbox MEDIUM 5.0
CVE-2007-5404

Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote att…

Mitigation only
Fix from $1,600 2008-01-09
Snitz Forums 2000 MEDIUM 5.0
CVE-2008-0136

Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the databa…

Mitigation only
Fix from $1,600 2008-01-08