Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2010-0523 Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive informatio… Mac Os X Server Mitigation only Fix from $1,6002010-03-30 MEDIUM 5.8 CVE-2010-1125 The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to sen… Firefox after 2.0.4 Fix from $1,6002010-03-26 MEDIUM 5.8 CVE-2010-1126 The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intende… Webkit Mitigation only Fix from $1,6002010-03-26 MEDIUM 5.0 CVE-2010-1007 Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensit… Ch Lightem after 1.0.34 Fix from $1,6002010-03-19 HIGH 7.1 CVE-2010-0572 Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related… Digital Media Manager after 5.1 Fix from $1,9502010-03-05 MEDIUM 5.0 CVE-2010-0667 MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable… Moinmoin Mitigation only Fix from $1,6002010-02-26 MEDIUM 5.0 CVE-2010-0670 Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path fo… Com Jquarks after 0.2.3 Fix from $1,6002010-02-22 MEDIUM 5.0 CVE-2010-0663 The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations… Chrome after 4.0.249.0 Fix from $1,6002010-02-18 MEDIUM 5.0 CVE-2010-0660 Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirect… Chrome after 4.0.249.0 Fix from $1,6002010-02-18 MEDIUM 5.0 CVE-2010-0642EPSS 8% Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extensio… Collaboration Server No fix yet Fix from $1,6002010-02-17 MEDIUM 5.0 CVE-2010-0563 The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configur… Websphere Application Server Patch available Fix from $1,6002010-02-08 MEDIUM 5.0 CVE-2010-0548 Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow … Workcentre 5632 Patch available Fix from $1,6002010-02-04 MEDIUM 5.0 CVE-2010-0549 Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Con… Workcentre 6400 Net Controller Patch available Fix from $1,6002010-02-04 MEDIUM 5.0 CVE-2010-0551 HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a … Geo\+\+ Gncaster after 1.4.0.7 Fix from $1,6002010-02-04 MEDIUM 5.0 CVE-2010-0463 Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it … Imp after 4.3.6 Fix from $1,6002010-01-29 MEDIUM 5.0 CVE-2010-0464 Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it … Webmail after 0.3.1 Fix from $1,6002010-01-29 MEDIUM 5.0 CVE-2009-4629 Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or A… Seamonkey Mitigation only Fix from $1,6002010-01-29 MEDIUM 5.0 CVE-2009-4630 Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML d… Firefox Mitigation only Fix from $1,6002010-01-29 MEDIUM 5.0 CVE-2010-0004 ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private… Viewvc Mitigation only Fix from $1,6002010-01-29 MEDIUM 5.4 CVE-2010-0003 The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, all… Linux Kernel 2.6.32.4+ Fix from $1,6002010-01-26 MEDIUM 5.0 CVE-2010-0383 Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man… Tor Mitigation only Fix from $1,6002010-01-25 MEDIUM 5.0 CVE-2010-0385 Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive … Tor Mitigation only Fix from $1,6002010-01-25 MEDIUM 5.0 CVE-2009-4609 The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via … Jetty No fix yet Fix from $1,6002010-01-13 MEDIUM 5.0 CVE-2009-4529 InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space ch… Navicopa Web Server after 3.0.1.2 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4530 Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI. Mongoose after 2.8 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4531EPSS 7% httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI. Httpdx after 1.4.4 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4533 The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholder… Webform after 6.x-2.7 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4535EPSS 7% Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI. Mongoose after 2.8.0 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4466 DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in… Deluxebb No fix yet Fix from $1,6002009-12-30 MEDIUM 5.0 CVE-2009-4357 CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might al… Rational Clearcase after 7.1 Fix from $1,6002009-12-18