Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2007-6660
2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request t…
2z Project
No fix yet
MEDIUM 5.0
CVE-2007-6606
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the ph…
Openbiblio
after 0.5.2_pre4
MEDIUM 5.0
CVE-2007-6607
OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mb…
Openbiblio
Patch available
MEDIUM 6.8
CVE-2007-6536
The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy conside…
Toolbar
No fix yet
HIGH 7.8
CVE-2007-6524
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CA…
Opera Browser
after 9.24
MEDIUM 5.0
CVE-2007-6512
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…
Mysql Banner Exchange
Mitigation only
MEDIUM 5.0
CVE-2007-6476
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo fun…
Gf 3xplorer
Patch available
MEDIUM 5.5
CVE-2007-6502
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel…
Hosting Controller
after 6.1_hotfix_3.3
HIGH 7.2
CVE-2007-6417
The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances rel…
Linux Kernel
Mitigation only
MEDIUM 6.4
CVE-2007-6405
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with …
Shttpd
No fix yet
MEDIUM 5.0
CVE-2007-6408
IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when c…
Tivoli Provisioning Manager Express
Mitigation only
HIGH 7.8
CVE-2007-6221
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo fun…
Tumusika Evolution
Mitigation only
MEDIUM 5.0
CVE-2007-6197
The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal …
Aqualogic Interaction
Patch available
MEDIUM 5.0
CVE-2007-6193
The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attacker…
Netscaler
Mitigation only
MEDIUM 5.0
CVE-2007-6161
index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search actio…
Tilde Cms
after 4.0
MEDIUM 5.0
CVE-2007-4688
The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addr…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2007-5922
The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally introduced …
Bitchx
Mitigation only
MEDIUM 5.0
CVE-2007-5816
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by making a request with an editauth…
Contentcustomizer
No fix yet
MEDIUM 5.0
CVE-2007-0011
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL…
Access Gateway
Patch available
MEDIUM 5.0
CVE-2007-5774
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a…
Flatnuke3
No fix yet
MEDIUM 5.0
CVE-2007-4861
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid…
Saxon
Mitigation only
HIGH 7.8
CVE-2007-5413
httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Confi…
Openview Client Configuraton Manager
Mitigation only
MEDIUM 5.0
CVE-2007-5654EPSS 41%
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new…
Litespeed Web Server
after 3.2.3
MEDIUM 5.0
CVE-2007-5379
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and r…
Ruby On Rails
after 1.2.3
MEDIUM 6.8
CVE-2007-5576
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically p…
Tuxedo
Mitigation only
MEDIUM 5.0
CVE-2007-5550
Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service"…
iOS
No fix yet
HIGH 7.1
CVE-2007-5554
Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the …
Database Server
Mitigation only
MEDIUM 6.9
CVE-2007-5555
Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Aut…
Altiris Deployment Solution
Patch available
MEDIUM 5.0
CVE-2007-5473
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files …
Mono
after 1.2.5.1
MEDIUM 6.8
CVE-2007-5195
Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…
Suse Linux
Patch available