Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2012-3838 Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) tem… Baby Gekko after 1.1.5 Fix from $1,6002012-07-03 MEDIUM 5.0 CVE-2012-3829 Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header. Joomla\! No fix yet Fix from $1,6002012-07-03 MEDIUM 5.0 CVE-2012-2815 Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access… Chrome after 20.0.1132.42 Fix from $1,6002012-06-27 MEDIUM 5.0 CVE-2012-3798 The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input u… Janrain Capture Patch available Fix from $1,6002012-06-27 MEDIUM 5.0 CVE-2012-3796EPSS 11% Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sens… Pro Server Ex after 3.1.00 Fix from $1,6002012-06-25 MEDIUM 6.0 CVE-2011-2707 The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local … Linux Kernel 3.1+ Fix from $1,6002012-05-24 MEDIUM 5.5 CVE-2011-2898 net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated … Linux Kernel 2.6.39.3+ Fix from $1,6002012-05-24 MEDIUM 5.0 CVE-2012-2922 The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] pa… Drupal after 7.14 Fix from $1,6002012-05-21 MEDIUM 5.0 CVE-2012-1249 The iLunascape application 1.0.4.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sen… Ilunascape Android after 1.0.4.0 Fix from $1,6002012-05-21 MEDIUM 5.0 CVE-2012-0651 The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a … Mac Os X Mitigation only Fix from $1,6002012-05-11 MEDIUM 5.0 CVE-2011-4232 The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists… Unified Meetingplace Mitigation only Fix from $1,6002012-05-03 MEDIUM 6.8 CVE-2012-0731 IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to… Rational Appscan Mitigation only Fix from $1,6002012-05-03 MEDIUM 5.0 CVE-2012-1243 The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitiv… Twitrocker2 Android Mitigation only Fix from $1,6002012-04-22 MEDIUM 5.0 CVE-2012-0130 HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors. Onboard Administrator after 3.32 Fix from $1,6002012-04-05 MEDIUM 5.0 CVE-2012-1670EPSS 8% admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action. Php Grade Book after 1.9.4 Fix from $1,6002012-03-31 MEDIUM 5.0 CVE-2012-1926 Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in c… Opera Browser after 11.61 Fix from $1,6002012-03-28 MEDIUM 5.0 CVE-2012-1920 @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to insta… Atmail Open after 1.04 Fix from $1,6002012-03-27 MEDIUM 5.0 CVE-2012-1837 The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOn… Tivoli Endpoint Manager after 8.1 Fix from $1,6002012-03-22 MEDIUM 5.0 CVE-2012-0328 Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors. Janetter after 3.2.1.1 Fix from $1,6002012-03-19 MEDIUM 5.0 CVE-2012-1464 Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" … Netdecision after 4.5.1 Fix from $1,6002012-03-19 MEDIUM 5.0 CVE-2012-1466 The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files wit… Netdecision after 4.5.1 Fix from $1,6002012-03-19 MEDIUM 5.0 CVE-2012-1786 The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation pat… Video Embed \& Thumbnail Generator after 1.1 Fix from $1,6002012-03-19 MEDIUM 5.0 CVE-2009-5112EPSS 5% wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. Webglimpse after 2.18.7 Fix from $1,6002012-03-19 MEDIUM 5.0 CVE-2012-0456 The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5… Firefox after 10.0 Fix from $1,6002012-03-14 MEDIUM 5.0 CVE-2012-0687 TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatri… Activematrix Service Bus after 5.9.2 Fix from $1,6002012-03-13 MEDIUM 5.0 CVE-2012-0689 The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x befor… Activematrix Bpm Mitigation only Fix from $1,6002012-03-13 MEDIUM 5.0 CVE-2012-0690 TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Serve… Spotfire Analytics Server after 4.0.1 Fix from $1,6002012-03-13 MEDIUM 5.0 CVE-2012-0640 WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remot… Safari after 5.1.3 Fix from $1,6002012-03-12 MEDIUM 5.0 CVE-2012-0647 WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers … Safari after 5.1.3 Fix from $1,6002012-03-12 MEDIUM 5.0 CVE-2012-0316 The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allow… Android Activities after 1.5.16 Fix from $1,6002012-03-02