Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
2z Project MEDIUM 5.0
CVE-2007-6660

2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request t…

No fix yet
Fix from $1,600 2008-01-04
Openbiblio MEDIUM 5.0
CVE-2007-6606

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the ph…

Fix: after 0.5.2_pre4
Fix from $1,600 2007-12-31
Openbiblio MEDIUM 5.0
CVE-2007-6607

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mb…

Patch available
Fix from $1,600 2007-12-31
Toolbar MEDIUM 6.8
CVE-2007-6536

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy conside…

No fix yet
Fix from $1,600 2007-12-27
Opera Browser HIGH 7.8
CVE-2007-6524

Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CA…

Fix: after 9.24
Fix from $1,950 2007-12-24
Mysql Banner Exchange MEDIUM 5.0
CVE-2007-6512

PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-12-21
Gf 3xplorer MEDIUM 5.0
CVE-2007-6476

GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo fun…

Patch available
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6502

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Linux Kernel HIGH 7.2
CVE-2007-6417

The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances rel…

Mitigation only
Fix from $1,950 2007-12-18
Shttpd MEDIUM 6.4
CVE-2007-6405

Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with …

No fix yet
Fix from $1,600 2007-12-17
Tivoli Provisioning Manager Express MEDIUM 5.0
CVE-2007-6408

IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when c…

Mitigation only
Fix from $1,600 2007-12-17
Tumusika Evolution HIGH 7.8
CVE-2007-6221

TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo fun…

Mitigation only
Fix from $1,950 2007-12-04
Aqualogic Interaction MEDIUM 5.0
CVE-2007-6197

The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal …

Patch available
Fix from $1,600 2007-12-01
Netscaler MEDIUM 5.0
CVE-2007-6193

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attacker…

Mitigation only
Fix from $1,600 2007-11-30
Tilde Cms MEDIUM 5.0
CVE-2007-6161

index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search actio…

Fix: after 4.0
Fix from $1,600 2007-11-29
Mac Os X MEDIUM 5.0
CVE-2007-4688

The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addr…

Patch available
Fix from $1,600 2007-11-15
Bitchx MEDIUM 5.0
CVE-2007-5922

The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally introduced …

Mitigation only
Fix from $1,600 2007-11-10
Contentcustomizer MEDIUM 5.0
CVE-2007-5816

dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editauth…

No fix yet
Fix from $1,600 2007-11-05
Access Gateway MEDIUM 5.0
CVE-2007-0011

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL…

Patch available
Fix from $1,600 2007-11-05
Flatnuke3 MEDIUM 5.0
CVE-2007-5774

index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a…

No fix yet
Fix from $1,600 2007-11-01
Saxon MEDIUM 5.0
CVE-2007-4861

SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid…

Mitigation only
Fix from $1,600 2007-10-30
Openview Client Configuraton Manager HIGH 7.8
CVE-2007-5413

httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Confi…

Mitigation only
Fix from $1,950 2007-10-29
Litespeed Web Server MEDIUM 5.0
CVE-2007-5654EPSS 41%

LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new…

Fix: after 3.2.3
Fix from $1,600 2007-10-23
Ruby On Rails MEDIUM 5.0
CVE-2007-5379

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and r…

Fix: after 1.2.3
Fix from $1,600 2007-10-19
Tuxedo MEDIUM 6.8
CVE-2007-5576

BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically p…

Mitigation only
Fix from $1,600 2007-10-18
iOS MEDIUM 5.0
CVE-2007-5550

Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service"…

No fix yet
Fix from $1,600 2007-10-18
Database Server HIGH 7.1
CVE-2007-5554

Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the …

Mitigation only
Fix from $1,950 2007-10-18
Altiris Deployment Solution MEDIUM 6.9
CVE-2007-5555

Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Aut…

Patch available
Fix from $1,600 2007-10-18
Mono MEDIUM 5.0
CVE-2007-5473

StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files …

Fix: after 1.2.5.1
Fix from $1,600 2007-10-18
Suse Linux MEDIUM 6.8
CVE-2007-5195

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Patch available
Fix from $1,600 2007-10-14