Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2008-1318
Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback param…
Mediawiki
Patch available
MEDIUM 5.0
CVE-2008-1288
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.
Rational Clearquest
Patch available
MEDIUM 5.0
CVE-2008-1270EPSS 12%
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitra…
Lighttpd
after 1.4.18
HIGH 10.0
CVE-2008-1252
b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading t…
Speedport W500 Dsl Router
No fix yet
MEDIUM 5.0
CVE-2008-1181
Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.c…
Secure Access 2000
Mitigation only
MEDIUM 5.0
CVE-2008-1166
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate…
Flyspray
Mitigation only
MEDIUM 5.0
CVE-2008-1111
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers…
Lighttpd
Mitigation only
MEDIUM 5.0
CVE-2007-6702
goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows …
Fs4104 Aw Device
No fix yet
MEDIUM 5.0
CVE-2008-1135
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed log…
Interneserviceslosungen
No fix yet
HIGH 7.8
CVE-2008-1113
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which al…
Vocera Communications Badge
Mitigation only
MEDIUM 5.0
CVE-2008-0978
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain s…
Double Take
No fix yet
HIGH 7.1
CVE-2008-0901
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout …
Weblogic Server
Patch available
HIGH 7.8
CVE-2008-0904
Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remo…
Aqualogic Interaction
Patch available
MEDIUM 5.0
CVE-2008-0863
BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain se…
Weblogic Server
Patch available
MEDIUM 5.0
CVE-2008-0784
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id paramete…
Cacti
Patch available
MEDIUM 5.0
CVE-2008-0736
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a ce…
Candypress Store
No fix yet
MEDIUM 5.0
CVE-2008-0041
Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determ…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2008-0636
Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct re…
Managed Workplace Service Center
No fix yet
HIGH 9.3
CVE-2008-0420
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not pr…
Firefox
after 2.0.0.11
MEDIUM 5.0
CVE-2007-5333EPSS 63%
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5…
Tomcat
after 6.0.14
HIGH 8.8
CVE-2008-0655 KEVEPSS 37%
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
Acrobat
8.1.2+
MEDIUM 5.0
CVE-2008-0395
Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints…
Supportsuite
Mitigation only
MEDIUM 5.0
CVE-2008-0367
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authen…
Firefox
after 2.0.0.11
MEDIUM 5.0
CVE-2007-5958EPSS 5%
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X progra…
Xserver
after 1.4
MEDIUM 5.0
CVE-2008-0297
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its ou…
Photokorn
No fix yet
MEDIUM 5.0
CVE-2008-0249
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the crede…
Phpwebquest
No fix yet
MEDIUM 5.0
CVE-2008-0191
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…
WordPress
Mitigation only
MEDIUM 5.0
CVE-2008-0195
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts …
WordPress
after 2.0.11
MEDIUM 5.0
CVE-2007-5404
Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote att…
Helpbox
Mitigation only
MEDIUM 5.0
CVE-2008-0136
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the databa…
Snitz Forums 2000
Mitigation only