Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.8 CVE-2009-3987 The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception me… Firefox after 3.0.15 Fix from $1,9502009-12-17 HIGH 7.5 CVE-2009-4333 The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD st… Db2 Patch available Fix from $1,9502009-12-16 MEDIUM 5.0 CVE-2009-4298 The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within t… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4300 Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, ev… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4303 Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers t… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 5.0 CVE-2009-4322 extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation p… Zen Cart No fix yet Fix from $1,6002009-12-14 HIGH 7.1 CVE-2009-3951 Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows re… Adobe Air after 10.0.32.18 Fix from $1,9502009-12-10 MEDIUM 5.0 CVE-2009-4254 PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_cssc… Pphlogger Mitigation only Fix from $1,6002009-12-10 MEDIUM 5.0 CVE-2009-4236 The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Commun… Ec Cube Ver2 Patch available Fix from $1,6002009-12-08 MEDIUM 5.0 CVE-2009-4175 CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_dat… Cutenews No fix yet Fix from $1,6002009-12-02 MEDIUM 5.0 CVE-2009-4170EPSS 6% WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to … Wp Cumulus No fix yet Fix from $1,6002009-12-02 MEDIUM 5.0 CVE-2009-4109 The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need… Dotnetnuke Mitigation only Fix from $1,6002009-11-29 MEDIUM 5.0 CVE-2009-3386 Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) D… Bugzilla Patch available Fix from $1,6002009-11-20 MEDIUM 5.0 CVE-2009-3946 Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct reques… Joomla\! after 1.5.14 Fix from $1,6002009-11-16 MEDIUM 5.0 CVE-2009-3727 Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x b… Asterisk Patch available Fix from $1,6002009-11-10 HIGH 7.5 CVE-2009-3881 Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which … Openjdk after 1.6.0 Fix from $1,9502009-11-09 HIGH 7.5 CVE-2009-3882 Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknow… Openjdk after 1.6.0 Fix from $1,9502009-11-09 HIGH 7.5 CVE-2009-3883 Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Upda… Openjdk after 1.6.0 Fix from $1,9502009-11-09 MEDIUM 5.0 CVE-2009-3815 RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to m… Runcms No fix yet Fix from $1,6002009-10-27 MEDIUM 5.0 CVE-2009-3756 phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in ad… Phpbms No fix yet Fix from $1,6002009-10-22 MEDIUM 5.0 CVE-2009-3646EPSS 6% InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DA… Navicopa Web Server No fix yet Fix from $1,6002009-10-09 MEDIUM 5.0 CVE-2009-3600 HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo functio… Hubscript No fix yet Fix from $1,6002009-10-08 MEDIUM 5.0 CVE-2009-3544 Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the H… Xerver No fix yet Fix from $1,6002009-10-05 MEDIUM 5.0 CVE-2009-3457 Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP requ… Ace Web Application Firewall after 6.0 Fix from $1,6002009-09-29 MEDIUM 5.0 CVE-2009-3452 WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigge… I Load after 2008.2.4.0 Fix from $1,6002009-09-29 MEDIUM 5.0 CVE-2009-3199 Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… Uebimiau No fix yet Fix from $1,6002009-09-15 MEDIUM 5.0 CVE-2009-2797 The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from… Ubuntu Linux 3.1 / 3.1.1+ Fix from $1,6002009-09-10 MEDIUM 5.0 CVE-2008-7187 Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, whic… Coppermine Photo Gallery Patch available Fix from $1,6002009-09-09 MEDIUM 5.0 CVE-2009-2266 OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other u… Eshop after 3.0.4.1 Fix from $1,6002009-09-09 MEDIUM 5.0 CVE-2009-3086 A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature … Rails Patch available Fix from $1,6002009-09-08