Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2008-4693 The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attacker… Db2 after 9.5 Fix from $1,6002008-10-22 MEDIUM 5.0 CVE-2008-4635 Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive u… Hisa Cart after 1.29 Fix from $1,6002008-10-21 MEDIUM 5.0 CVE-2008-4412 Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive informa… Systems Insight Manager after 5.2 Fix from $1,6002008-10-17 MEDIUM 5.0 CVE-2008-4491 Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s… Mail Mitigation only Fix from $1,6002008-10-08 MEDIUM 5.0 CVE-2008-3060 V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) … V Webmail Mitigation only Fix from $1,6002008-10-08 HIGH 7.5 CVE-2008-4359 lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w… Debian Linux 1.4.20+ Fix from $1,9502008-10-03 HIGH 7.5 CVE-2008-4360 mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam… Debian Linux 1.4.20+ Fix from $1,9502008-10-03 MEDIUM 5.0 CVE-2008-4199 Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determin… Opera Browser after 9.51 Fix from $1,6002008-09-27 MEDIUM 5.0 CVE-2008-4069 The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obt… Firefox after 2.0.0.16 Fix from $1,6002008-09-24 MEDIUM 5.0 CVE-2008-4207 Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive informat… Dolphin No fix yet Fix from $1,6002008-09-24 MEDIUM 5.0 CVE-2008-4180 Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbu… Nooms No fix yet Fix from $1,6002008-09-23 MEDIUM 5.0 CVE-2008-4183 IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup… Integramod No fix yet Fix from $1,6002008-09-23 MEDIUM 5.0 CVE-2008-4170 create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in… Oscommerce Mitigation only Fix from $1,6002008-09-22 MEDIUM 5.0 CVE-2008-4125 The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially s… Phpbb Mitigation only Fix from $1,6002008-09-18 MEDIUM 5.0 CVE-2008-4115 TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. Talkback No fix yet Fix from $1,6002008-09-16 MEDIUM 5.0 CVE-2008-3274 The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, w… Enterprise Ipa after 1.1.0 Fix from $1,6002008-09-12 HIGH 10.0 CVE-2008-3914 Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path… Clamav after 0.93.3 Fix from $1,9502008-09-11 HIGH 7.1 CVE-2008-2736 Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clie… Adaptive Security Appliance 5500 Mitigation only Fix from $1,9502008-09-04 MEDIUM 5.0 CVE-2008-3514 VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which a… Virtualcenter after 2.0.2 Fix from $1,6002008-08-13 HIGH 10.0 CVE-2008-0082EPSS 34% An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to cont… Windows Messenger Mitigation only Fix from $1,9502008-08-13 HIGH 7.8 CVE-2008-2246EPSS 32% Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Se… Windows Nt Patch available Fix from $1,9502008-08-13 MEDIUM 5.0 CVE-2008-3550 The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co… Rational Clearquest Mitigation only Fix from $1,6002008-08-08 MEDIUM 5.0 CVE-2008-3458 Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail … Vtiger Crm after 5.0.3 Fix from $1,6002008-08-04 MEDIUM 6.8 CVE-2008-3339 search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path… Jobbex Jobsite Patch available Fix from $1,6002008-07-28 MEDIUM 5.0 CVE-2008-3304EPSS 6% BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct requ… Bilboblog No fix yet Fix from $1,6002008-07-25 MEDIUM 5.0 CVE-2008-3168 The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed. Empire Server after 4.3.11 Fix from $1,6002008-07-14 MEDIUM 5.0 CVE-2008-3171 Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive … Safari Mitigation only Fix from $1,6002008-07-14 MEDIUM 5.0 CVE-2008-2318 The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remo… Xcode after 3.0 Fix from $1,6002008-07-14 MEDIUM 5.0 CVE-2008-3138 The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (app… Wireshark Mitigation only Fix from $1,6002008-07-10 MEDIUM 5.0 CVE-2008-3139 The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown ve… Wireshark Mitigation only Fix from $1,6002008-07-10