Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Suse Linux HIGH 7.5
CVE-2007-5196

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Mitigation only
Fix from $1,950 2007-10-14
Cms Made Simple MEDIUM 5.0
CVE-2007-5444

CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files.

No fix yet
Fix from $1,600 2007-10-14
Etrust Integrated Threat Management MEDIUM 5.0
CVE-2007-5439

CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows…

Mitigation only
Fix from $1,600 2007-10-13
Myftpuploader Module HIGH 7.8
CVE-2007-5431

include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow re…

No fix yet
Fix from $1,950 2007-10-12
Stride Cms HIGH 7.5
CVE-2007-5432

Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access…

Mitigation only
Fix from $1,950 2007-10-12
Dropteam MEDIUM 5.0
CVE-2007-5264

Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to…

Fix: after 1.3.3
Fix from $1,600 2007-10-08
Quicksilver Forums MEDIUM 5.0
CVE-2007-5172

Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the d…

Fix: after 1.4.0
Fix from $1,600 2007-10-01
Simpgb MEDIUM 5.0
CVE-2007-5129

SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitiv…

Patch available
Fix from $1,600 2007-09-27
Isa Server MEDIUM 5.0
CVE-2007-4991EPSS 16%

The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitiv…

Patch available
Fix from $1,600 2007-09-21
Dibbler HIGH 7.5
CVE-2007-5028

Dibbler 0.6.0 on Linux uses weak world-writable permissions for unspecified files in /var/lib/dibbler, which has unknown impact and local attack vect…

Patch available
Fix from $1,950 2007-09-21
Tivoli Storage Manager Client MEDIUM 5.0
CVE-2007-5022

Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 bef…

Fix: 5.1.8.1 / 5.2.5.2+
Fix from $1,600 2007-09-21
Webbatch MEDIUM 5.0
CVE-2007-5011

webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.

Fix: after 2007c
Fix from $1,600 2007-09-20
Shopping Basket Professional MEDIUM 5.0
CVE-2007-4655

Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary dir…

Fix: after 7.51
Fix from $1,600 2007-09-04
.net Framework HIGH 7.8
CVE-2007-0042EPSS 76%

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers…

Mitigation only
Fix from $1,950 2007-07-10
Firefox MEDIUM 6.8
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote …

No fix yet
Fix from $1,600 2007-07-10
Psychostats MEDIUM 5.0
CVE-2007-2780

PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newthem…

Fix: after 3.0.6b
Fix from $1,600 2007-05-21
Groupwise Mobile Server MEDIUM 6.4
CVE-2007-2590

Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Ema…

Patch available
Fix from $1,600 2007-05-11
Wikkawiki MEDIUM 5.0
CVE-2007-2552

The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates…

Fix: after 1.1.6.2
Fix from $1,600 2007-05-09
Trillian MEDIUM 5.9
CVE-2007-2479

Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that con…

Mitigation only
Fix from $1,600 2007-05-03
Jquery MEDIUM 5.0
CVE-2007-2379

The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to…

Mitigation only
Fix from $1,600 2007-04-30
Axis MEDIUM 5.0
CVE-2007-2353EPSS 28%

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path i…

No fix yet
Fix from $1,600 2007-04-30
Exponent Cms MEDIUM 5.0
CVE-2007-2253

Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and …

Fix: after 0.96.6_alpha
Fix from $1,600 2007-04-25
Flash Player MEDIUM 6.8
CVE-2007-2022

Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive inf…

Mitigation only
Fix from $1,600 2007-04-13
Firefox MEDIUM 6.8
CVE-2007-1562EPSS 14%

The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to o…

Fix: 1.5.0.11 / 2.0.0.3+
Fix from $1,600 2007-03-21
Opera Browser MEDIUM 6.8
CVE-2007-1563

The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perfo…

Mitigation only
Fix from $1,600 2007-03-21
Konqueror MEDIUM 6.8
CVE-2007-1564

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan…

Mitigation only
Fix from $1,600 2007-03-21
Sitex MEDIUM 5.0
CVE-2007-1237

sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters…

No fix yet
Fix from $1,600 2007-03-03
Dev\!l\'z Clanportal MEDIUM 5.0
CVE-2007-1167

inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value o…

Fix: after 1.4.5
Fix from $1,600 2007-03-02
Firefox MEDIUM 5.0
CVE-2007-1116

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attac…

Patch available
Fix from $1,600 2007-02-26
Firefox MEDIUM 5.4
CVE-2007-0778

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause …

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26