Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2009-3987
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception me…
Firefox
after 3.0.15
HIGH 7.5
CVE-2009-4333
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st…
Db2
Patch available
MEDIUM 5.0
CVE-2009-4298
The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within t…
Moodle
Patch available
MEDIUM 5.0
CVE-2009-4300
Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, ev…
Moodle
Patch available
MEDIUM 5.0
CVE-2009-4303
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers t…
Moodle
Patch available
MEDIUM 5.0
CVE-2009-4322
extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation p…
Zen Cart
No fix yet
HIGH 7.1
CVE-2009-3951
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows re…
Adobe Air
after 10.0.32.18
MEDIUM 5.0
CVE-2009-4254
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_cssc…
Pphlogger
Mitigation only
MEDIUM 5.0
CVE-2009-4236
The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Commun…
Ec Cube Ver2
Patch available
MEDIUM 5.0
CVE-2009-4175
CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_dat…
Cutenews
No fix yet
MEDIUM 5.0
CVE-2009-4170EPSS 6%
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to …
Wp Cumulus
No fix yet
MEDIUM 5.0
CVE-2009-4109
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need…
Dotnetnuke
Mitigation only
MEDIUM 5.0
CVE-2009-3386
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) D…
Bugzilla
Patch available
MEDIUM 5.0
CVE-2009-3946
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct reques…
Joomla\!
after 1.5.14
MEDIUM 5.0
CVE-2009-3727
Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x b…
Asterisk
Patch available
HIGH 7.5
CVE-2009-3881
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which …
Openjdk
after 1.6.0
HIGH 7.5
CVE-2009-3882
Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknow…
Openjdk
after 1.6.0
HIGH 7.5
CVE-2009-3883
Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Upda…
Openjdk
after 1.6.0
MEDIUM 5.0
CVE-2009-3815
RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to m…
Runcms
No fix yet
MEDIUM 5.0
CVE-2009-3756
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in ad…
Phpbms
No fix yet
MEDIUM 5.0
CVE-2009-3646EPSS 6%
InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DA…
Navicopa Web Server
No fix yet
MEDIUM 5.0
CVE-2009-3600
HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo functio…
Hubscript
No fix yet
MEDIUM 5.0
CVE-2009-3544
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the H…
Xerver
No fix yet
MEDIUM 5.0
CVE-2009-3457
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP requ…
Ace Web Application Firewall
after 6.0
MEDIUM 5.0
CVE-2009-3452
WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigge…
I Load
after 2008.2.4.0
MEDIUM 5.0
CVE-2009-3199
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…
Uebimiau
No fix yet
MEDIUM 5.0
CVE-2009-2797
The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from…
Ubuntu Linux
3.1 / 3.1.1+
MEDIUM 5.0
CVE-2008-7187
Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, whic…
Coppermine Photo Gallery
Patch available
MEDIUM 5.0
CVE-2009-2266
OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other u…
Eshop
after 3.0.4.1
MEDIUM 5.0
CVE-2009-3086
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature …
Rails
Patch available