Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2011-3011EPSS 72% BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently… Arcserve D2d No fix yet Fix from $1,6002011-08-15 MEDIUM 5.0 CVE-2011-3126 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects. WordPress Patch available Fix from $1,6002011-08-10 MEDIUM 5.0 CVE-2011-3128 WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive d… WordPress Patch available Fix from $1,6002011-08-10 MEDIUM 5.0 CVE-2011-2380 Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.… Bugzilla Patch available Fix from $1,6002011-08-09 MEDIUM 5.0 CVE-2011-2720 The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obta… Glpi after 0.80.1 Fix from $1,6002011-08-05 MEDIUM 5.0 CVE-2011-2488 Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors. Joomla\! after 1.5.22 Fix from $1,6002011-07-27 MEDIUM 5.0 CVE-2011-2889 templates/system/error.php in Joomla! before 1.5.23 might allow remote attackers to obtain sensitive information via unspecified vectors that trigger… Joomla\! after 1.5.22 Fix from $1,6002011-07-27 MEDIUM 5.0 CVE-2011-2890 The MediaViewMedia class in administrator/components/com_media/views/media/view.html.php in Joomla! 1.5.23 and earlier allows remote attackers to obt… Joomla\! after 1.5.23 Fix from $1,6002011-07-27 MEDIUM 5.0 CVE-2011-2891 Joomla! 1.6.x before 1.6.2 allows remote attackers to obtain sensitive information via an empty Itemid array parameter to index.php, which reveals th… Joomla\! No fix yet Fix from $1,6002011-07-27 MEDIUM 5.0 CVE-2011-2759 The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an o… Tivoli Directory Server Mitigation only Fix from $1,6002011-07-17 MEDIUM 5.0 CVE-2011-2536 chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk… Asterisk Patch available Fix from $1,6002011-07-06 MEDIUM 5.0 CVE-2011-1173 The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain pote… Linux Kernel 2.6.39+ Fix from $1,6002011-06-22 MEDIUM 5.0 CVE-2011-1131 The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation… Smf after 1.1.12 Fix from $1,6002011-06-21 MEDIUM 5.0 CVE-2011-1647 The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N … Rvs4000 Mitigation only Fix from $1,6002011-05-31 MEDIUM 5.0 CVE-2011-2152 The SmarterTools SmarterStats 6.0 web server generates web pages containing external links in response to GET requests with query strings for (1) Cli… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 5.0 CVE-2011-2153 Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes i… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 5.0 CVE-2011-2154 login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, wh… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 5.0 CVE-2011-2156 The SmarterTools SmarterStats 6.0 web server allows remote attackers to obtain directory listings via a direct request for the (1) Admin/, (2) Admin/… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 5.0 CVE-2011-2088EPSS 6% XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive informati… Struts Patch available Fix from $1,6002011-05-13 MEDIUM 5.0 CVE-2011-2076 MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by readi… Mediacast after 8 Fix from $1,6002011-05-10 MEDIUM 5.0 CVE-2011-2081 MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote atta… Mediacast after 8 Fix from $1,6002011-05-10 MEDIUM 5.0 CVE-2011-1839 IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for… Rational Build Forge Mitigation only Fix from $1,6002011-04-28 MEDIUM 5.0 CVE-2011-1725 Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknow… Network Automation No fix yet Fix from $1,6002011-04-27 MEDIUM 6.4 CVE-2009-0788 Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecifie… Network Satellite Server No fix yet Fix from $1,6002011-04-18 MEDIUM 5.0 CVE-2011-1672 The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitiv… Kace K2000 Systems Deployment Appliance after 3.3.36822 Fix from $1,6002011-04-10 MEDIUM 5.0 CVE-2011-1666 Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (… Tine No fix yet Fix from $1,6002011-04-10 MEDIUM 5.0 CVE-2010-4781 index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive inform… Enano Cms after 1.1.7 Fix from $1,6002011-04-07 MEDIUM 5.0 CVE-2011-1569 download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2… Portal No fix yet Fix from $1,6002011-04-05 MEDIUM 5.0 CVE-2011-0890 HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configur… Discovery\&dependency Mapping Inventory Mitigation only Fix from $1,6002011-03-25 MEDIUM 5.0 CVE-2011-1418 The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4… Iphone Os after 4.2 Fix from $1,6002011-03-11