Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Visnetic Website MEDIUM 5.0
CVE-2003-0456

VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which l…

Patch available
Fix from $1,600 2003-08-18
A Cart MEDIUM 5.0
CVE-2002-1432EPSS 8%

MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly …

Patch available
Fix from $1,600 2003-04-11
FreeBSD MEDIUM 5.0
CVE-2003-0001EPSS 73%

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information …

Mitigation only
Fix from $1,600 2003-01-17
Internet Information Services MEDIUM 5.0
CVE-2002-1717EPSS 16%

Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1718EPSS 14%

Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim…

Mitigation only
Fix from $1,600 2002-12-31
Ultimate Php Board MEDIUM 5.0
CVE-2002-2276

Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the …

No fix yet
Fix from $1,600 2002-12-31
Site Server MEDIUM 5.0
CVE-2002-2288

Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that doe…

Patch available
Fix from $1,600 2002-12-31
Badblue MEDIUM 5.0
CVE-2002-2289

soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

No fix yet
Fix from $1,600 2002-12-31
Velociraptor HIGH 7.8
CVE-2002-2317

Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumpt…

Patch available
Fix from $1,950 2002-12-31
Bannermatic MEDIUM 5.0
CVE-2002-2342

Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient …

Mitigation only
Fix from $1,600 2002-12-31
Phpbb MEDIUM 5.0
CVE-2002-2346

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers…

Mitigation only
Fix from $1,600 2002-12-31
Phpbbmod MEDIUM 5.0
CVE-2002-2349

phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.

No fix yet
Fix from $1,600 2002-12-31
Liteserve MEDIUM 5.0
CVE-2002-2369

Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.

Patch available
Fix from $1,600 2002-12-31
Network Firmware MEDIUM 6.4
CVE-2002-2380EPSS 11%

NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u…

Mitigation only
Fix from $1,600 2002-12-31
Open Webmail MEDIUM 5.0
CVE-2002-2410

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists o…

No fix yet
Fix from $1,600 2002-12-31
Internet Information Server MEDIUM 5.0
CVE-2002-0419EPSS 38%

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks …

No fix yet
Fix from $1,600 2002-08-12
Compaq Wl310 Firmware MEDIUM 6.4
CVE-2002-0812

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default S…

Mitigation only
Fix from $1,600 2002-08-12
Reporting Center MEDIUM 5.0
CVE-2002-0596

WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty…

Patch available
Fix from $1,600 2002-06-18
Wftpd MEDIUM 5.0
CVE-2000-0876

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message…

Mitigation only
Fix from $1,600 2000-11-14
Sawmill MEDIUM 5.0
CVE-2000-0588EPSS 7%

SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose content…

No fix yet
Fix from $1,600 2000-06-26
Big Brother MEDIUM 5.0
CVE-1999-1462

Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attackers to read portions of arbitrary files.

Patch available
Fix from $1,600 1999-12-31
Merchant Order Form MEDIUM 5.0
CVE-1999-0605

An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.

No fix yet
Fix from $1,600 1999-04-01
Ezmall MEDIUM 5.0
CVE-1999-0606

An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.

Mitigation only
Fix from $1,600 1999-04-01
Internet Information Server MEDIUM 5.0
CVE-1999-0348EPSS 11%

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

Mitigation only
Fix from $1,600 1999-01-27
Router MEDIUM 5.0
CVE-1999-0453

An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).

Mitigation only
Fix from $1,600 1999-01-01
Unclassified HIGH 7.3
CVE-1999-0632

The RPC portmapper service is running.

Mitigation only
Fix from $1,950 1999-01-01
Irix HIGH 7.3
CVE-1999-0059

IRIX fam service allows an attacker to obtain a list of all files on the server.

Mitigation only
Fix from $1,950 1997-07-14
Windows 2000 CRITICAL 9.1
CVE-1999-0511EPSS 7%

IP forwarding is enabled on a machine which is not a router or firewall.

Mitigation only
Fix from $2,300 1997-01-01
Hp Ux MEDIUM 5.9
CVE-1999-0517EPSS 27%

An SNMP community name is the default (e.g. public), null, or missing.

Mitigation only
Fix from $1,600 1997-01-01