Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2008-3114
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.…
Jdk
after 6
MEDIUM 5.3
CVE-2007-3650
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through i…
Mybloggie
No fix yet
MEDIUM 5.3
CVE-2007-3651
class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence …
Faname
No fix yet
HIGH 7.8
CVE-2008-3078
Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized…
Opera Browser
after 9.50
MEDIUM 5.0
CVE-2008-0085EPSS 11%
SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE…
Data Engine
Patch available
MEDIUM 5.0
CVE-2008-2807
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote att…
Firefox
after 2.0.0.14
MEDIUM 5.0
CVE-2008-3040
Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive inform…
Dam Frontend Extension
after 0.1.0
MEDIUM 5.0
CVE-2008-3049
The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.
Pdf Generator 2 Extension
after 0.5.0
MEDIUM 5.0
CVE-2008-2881
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain se…
Relative Real Estate Systems
after 3.0
MEDIUM 5.0
CVE-2008-2864
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2…
Site Composer
after 2.6
HIGH 7.5
CVE-2008-2782
Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) …
Otomigenx
No fix yet
MEDIUM 5.0
CVE-2008-2721
Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by att…
Gallery
after 2.2.4
MEDIUM 5.0
CVE-2008-2723
embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address…
Gallery
after 2.2.4
MEDIUM 5.0
CVE-2008-2715
Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as pat…
Opera Browser
after 9.50
MEDIUM 5.0
CVE-2008-2681
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database…
Realm Cms
after 2.3
MEDIUM 5.0
CVE-2008-1579
Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message pr…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2008-2120
Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update…
Java System Application Server
after 7.0
MEDIUM 5.8
CVE-2008-2027
Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such…
Authentication Agent
Mitigation only
HIGH 10.0
CVE-2008-1155
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to ob…
Network Admission Control
after 4.1.1
MEDIUM 5.0
CVE-2008-1782
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.
Chartdirector
No fix yet
HIGH 7.5
CVE-2008-1752
ezRADIUS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials vi…
Ezradius
Mitigation only
MEDIUM 5.0
CVE-2008-1717
WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) f…
Burning Board
Mitigation only
MEDIUM 5.0
CVE-2008-1618
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes dependi…
Firebox Pptp Vpn
Patch available
MEDIUM 5.0
CVE-2008-1680
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals se…
Php Nuke Platinum
No fix yet
MEDIUM 5.0
CVE-2008-1557
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, whic…
Bolinos
No fix yet
MEDIUM 5.1
CVE-2008-1156
Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attack…
Cisco Ios
Patch available
MEDIUM 5.0
CVE-2008-1523
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to o…
Prestige 660
Mitigation only
MEDIUM 5.0
CVE-2008-1506
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpi…
Peel
after 3.0
MEDIUM 6.8
CVE-2008-0052
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2008-0050
CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.
Mac Os X
Patch available