Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2008-1318 Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback param… Mediawiki Patch available Fix from $1,6002008-03-13 MEDIUM 5.0 CVE-2008-1288 IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies. Rational Clearquest Patch available Fix from $1,6002008-03-11 MEDIUM 5.0 CVE-2008-1270EPSS 12% mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitra… Lighttpd after 1.4.18 Fix from $1,6002008-03-10 HIGH 10.0 CVE-2008-1252 b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading t… Speedport W500 Dsl Router No fix yet Fix from $1,9502008-03-10 MEDIUM 5.0 CVE-2008-1181 Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.c… Secure Access 2000 Mitigation only Fix from $1,6002008-03-06 MEDIUM 5.0 CVE-2008-1166 Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate… Flyspray Mitigation only Fix from $1,6002008-03-05 MEDIUM 5.0 CVE-2008-1111 mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers… Lighttpd Mitigation only Fix from $1,6002008-03-04 MEDIUM 5.0 CVE-2007-6702 goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows … Fs4104 Aw Device No fix yet Fix from $1,6002008-03-04 MEDIUM 5.0 CVE-2008-1135 OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed log… Interneserviceslosungen No fix yet Fix from $1,6002008-03-04 HIGH 7.8 CVE-2008-1113 Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which al… Vocera Communications Badge Mitigation only Fix from $1,9502008-03-03 MEDIUM 5.0 CVE-2008-0978 Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain s… Double Take No fix yet Fix from $1,6002008-02-25 HIGH 7.1 CVE-2008-0901 BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout … Weblogic Server Patch available Fix from $1,9502008-02-22 HIGH 7.8 CVE-2008-0904 Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remo… Aqualogic Interaction Patch available Fix from $1,9502008-02-22 MEDIUM 5.0 CVE-2008-0863 BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain se… Weblogic Server Patch available Fix from $1,6002008-02-21 MEDIUM 5.0 CVE-2008-0784 graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id paramete… Cacti Patch available Fix from $1,6002008-02-14 MEDIUM 5.0 CVE-2008-0736 admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a ce… Candypress Store No fix yet Fix from $1,6002008-02-13 MEDIUM 5.0 CVE-2008-0041 Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determ… Mac Os X Patch available Fix from $1,6002008-02-12 MEDIUM 5.0 CVE-2008-0636 Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct re… Managed Workplace Service Center No fix yet Fix from $1,6002008-02-12 HIGH 9.3 CVE-2008-0420 modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not pr… Firefox after 2.0.0.11 Fix from $1,9502008-02-12 MEDIUM 5.0 CVE-2007-5333EPSS 63% Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5… Tomcat after 6.0.14 Fix from $1,6002008-02-12 HIGH 8.8 CVE-2008-0655 KEVEPSS 37% Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. Acrobat 8.1.2+ Fix from $1,9502008-02-07 MEDIUM 5.0 CVE-2008-0395 Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints… Supportsuite Mitigation only Fix from $1,6002008-01-23 MEDIUM 5.0 CVE-2008-0367 Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authen… Firefox after 2.0.0.11 Fix from $1,6002008-01-19 MEDIUM 5.0 CVE-2007-5958EPSS 5% X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X progra… Xserver after 1.4 Fix from $1,6002008-01-18 MEDIUM 5.0 CVE-2008-0297 PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its ou… Photokorn No fix yet Fix from $1,6002008-01-16 MEDIUM 5.0 CVE-2008-0249 PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the crede… Phpwebquest No fix yet Fix from $1,6002008-01-12 MEDIUM 5.0 CVE-2008-0191 WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh… WordPress Mitigation only Fix from $1,6002008-01-10 MEDIUM 5.0 CVE-2008-0195 WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts … WordPress after 2.0.11 Fix from $1,6002008-01-10 MEDIUM 5.0 CVE-2007-5404 Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote att… Helpbox Mitigation only Fix from $1,6002008-01-09 MEDIUM 5.0 CVE-2008-0136 Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the databa… Snitz Forums 2000 Mitigation only Fix from $1,6002008-01-08