Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2009-5122 The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from t… Websense Email Security after 7.1 Fix from $1,6002012-08-23 MEDIUM 5.0 CVE-2012-4591 About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, wh… Enterprise Mobility Manager after 9.6 Fix from $1,6002012-08-22 MEDIUM 5.0 CVE-2012-4219 show_config_errors.php in phpMyAdmin 3.5.x before 3.5.2.1 allows remote attackers to obtain sensitive information via a direct request, which reveals… phpMyAdmin Patch available Fix from $1,6002012-08-21 MEDIUM 5.0 CVE-2012-2387 devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers… Devotee Mitigation only Fix from $1,6002012-08-20 MEDIUM 5.0 CVE-2012-0744EPSS 8% IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a reque… Rational Clearquest Mitigation only Fix from $1,6002012-08-17 MEDIUM 5.0 CVE-2012-3248 HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors. Fortify Software Security Center No fix yet Fix from $1,6002012-08-16 MEDIUM 5.0 CVE-2012-4332 The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK. Shareyourcart No fix yet Fix from $1,6002012-08-14 MEDIUM 5.0 CVE-2012-4256 The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveal… Com Jnews No fix yet Fix from $1,6002012-08-13 MEDIUM 5.0 CVE-2012-4257 Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPS… Yet Another Question \& Answer System No fix yet Fix from $1,6002012-08-13 MEDIUM 5.0 CVE-2012-2327 MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the i… Mybb after 1.6.6 Fix from $1,6002012-08-13 MEDIUM 5.0 CVE-2012-3474 The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensit… Ushahidi Platform after 2.4.1 Fix from $1,6002012-08-12 MEDIUM 5.0 CVE-2012-4235 The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote at… Com Rsgallery2 after 3.1.0 Fix from $1,6002012-08-10 MEDIUM 5.0 CVE-2012-4005 The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sens… Nhn Japan Naver Line after 2.5 Fix from $1,6002012-08-07 MEDIUM 5.0 CVE-2012-1348 Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which… Wide Area Application Services Mitigation only Fix from $1,6002012-08-06 MEDIUM 5.0 CVE-2012-2854 Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain poten… Chrome after 21.0.1180.56 Fix from $1,6002012-08-06 MEDIUM 5.8 CVE-2012-2647 Yahoo! Toolbar 1.0.0.5 and earlier for Chrome and Safari allows remote attackers to modify the configured search URL, and intercept search terms, via… Toolbar after 1.0.0.5 Fix from $1,6002012-07-31 MEDIUM 5.0 CVE-2012-3886 AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attackers to o… Airdroid No fix yet Fix from $1,6002012-07-26 MEDIUM 5.0 CVE-2012-2296 The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data from Engage … Rpx Patch available Fix from $1,6002012-07-25 MEDIUM 5.0 CVE-2012-2302 Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote a… Sitedoc Patch available Fix from $1,6002012-07-25 MEDIUM 5.0 CVE-2012-2646 The Sleipnir Mobile application before 2.1.0 and Sleipnir Mobile Black Edition application before 2.1.0 for Android do not properly implement the Web… Sleipnir Mobile 2.1.0+ Fix from $1,6002012-07-25 MEDIUM 5.0 CVE-2012-2196 IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) … Db2 Mitigation only Fix from $1,6002012-07-25 MEDIUM 5.0 CVE-2012-3394 auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 5.0 CVE-2012-3357 The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from … Viewvc after 1.1.14 Fix from $1,6002012-07-22 MEDIUM 5.0 CVE-2012-2357 The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 5.0 CVE-2012-1960 The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and S… Firefox after 2.10 Fix from $1,6002012-07-18 MEDIUM 5.0 CVE-2011-4279 Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attacke… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4283 Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to … Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2011-4284 Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context … Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.0 CVE-2012-3996 TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php… Tikiwiki Cms\/groupware after 8.2 Fix from $1,6002012-07-12 MEDIUM 5.0 CVE-2012-3838 Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) tem… Baby Gekko after 1.1.5 Fix from $1,6002012-07-03