Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2008-4693
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attacker…
Db2
after 9.5
MEDIUM 5.0
CVE-2008-4635
Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive u…
Hisa Cart
after 1.29
MEDIUM 5.0
CVE-2008-4412
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive informa…
Systems Insight Manager
after 5.2
MEDIUM 5.0
CVE-2008-4491
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s…
Mail
Mitigation only
MEDIUM 5.0
CVE-2008-3060
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) …
V Webmail
Mitigation only
HIGH 7.5
CVE-2008-4359
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w…
Debian Linux
1.4.20+
HIGH 7.5
CVE-2008-4360
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam…
Debian Linux
1.4.20+
MEDIUM 5.0
CVE-2008-4199
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determin…
Opera Browser
after 9.51
MEDIUM 5.0
CVE-2008-4069
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obt…
Firefox
after 2.0.0.16
MEDIUM 5.0
CVE-2008-4207
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive informat…
Dolphin
No fix yet
MEDIUM 5.0
CVE-2008-4180
Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbu…
Nooms
No fix yet
MEDIUM 5.0
CVE-2008-4183
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup…
Integramod
No fix yet
MEDIUM 5.0
CVE-2008-4170
create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the in…
Oscommerce
Mitigation only
MEDIUM 5.0
CVE-2008-4125
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially s…
Phpbb
Mitigation only
MEDIUM 5.0
CVE-2008-4115
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Talkback
No fix yet
MEDIUM 5.0
CVE-2008-3274
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, w…
Enterprise Ipa
after 1.1.0
HIGH 10.0
CVE-2008-3914
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path…
Clamav
after 0.93.3
HIGH 7.1
CVE-2008-2736
Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clie…
Adaptive Security Appliance 5500
Mitigation only
MEDIUM 5.0
CVE-2008-3514
VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which a…
Virtualcenter
after 2.0.2
HIGH 10.0
CVE-2008-0082EPSS 34%
An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to cont…
Windows Messenger
Mitigation only
HIGH 7.8
CVE-2008-2246EPSS 32%
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Se…
Windows Nt
Patch available
MEDIUM 5.0
CVE-2008-3550
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a co…
Rational Clearquest
Mitigation only
MEDIUM 5.0
CVE-2008-3458
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail …
Vtiger Crm
after 5.0.3
MEDIUM 6.8
CVE-2008-3339
search_result.cfm in Jobbex JobSite allows remote attackers to obtain sensitive information via unspecified vectors that reveal the installation path…
Jobbex Jobsite
Patch available
MEDIUM 5.0
CVE-2008-3304EPSS 6%
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct requ…
Bilboblog
No fix yet
MEDIUM 5.0
CVE-2008-3168
The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.
Empire Server
after 4.3.11
MEDIUM 5.0
CVE-2008-3171
Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive …
Safari
Mitigation only
MEDIUM 5.0
CVE-2008-2318
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remo…
Xcode
after 3.0
MEDIUM 5.0
CVE-2008-3138
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (app…
Wireshark
Mitigation only
MEDIUM 5.0
CVE-2008-3139
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown ve…
Wireshark
Mitigation only