Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2005-4368 roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of th… Webmail Mitigation only Fix from $1,6002005-12-20 MEDIUM 5.0 CVE-2005-4320 Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2)… Limbo Cms after 1.0.4.2 Fix from $1,6002005-12-17 MEDIUM 5.0 CVE-2005-4214 phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message be… Phpcoin No fix yet Fix from $1,6002005-12-14 MEDIUM 5.0 CVE-2005-3747 Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp file… Jetty after 5.1.5 Fix from $1,6002005-11-22 MEDIUM 6.4 CVE-2005-3724 Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a … P2000w Version 1 Voip Wifi Phone Mitigation only Fix from $1,6002005-11-21 MEDIUM 5.0 CVE-2005-3529 tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode pa… Tikiwiki Cms\/groupware No fix yet Fix from $1,6002005-11-20 MEDIUM 5.0 CVE-2005-3645 phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive in… Phpadsnew Patch available Fix from $1,6002005-11-17 HIGH 7.5 CVE-2005-2036 modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nick… Cool Cafe Chat No fix yet Fix from $1,9502005-06-16 MEDIUM 5.0 CVE-2005-1028 PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter… Php Nuke after 7.6 Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0797 Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive inform… Mitigation only Fix from $1,6002005-03-15 MEDIUM 5.3 CVE-2004-2320 The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds… Weblogic Server Patch available Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-1923 Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (… Tikiwiki Cms\/groupware after 1.8.1 Fix from $1,6002004-04-11 MEDIUM 6.0 CVE-2003-0904EPSS 8% Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can… Exchange Server Patch available Fix from $1,6002004-01-20 MEDIUM 5.0 CVE-2003-1379 clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reve… Clarkconnect Patch available Fix from $1,6002003-12-31 HIGH 9.3 CVE-2003-1398 Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of se… iOS Mitigation only Fix from $1,9502003-12-31 HIGH 7.5 CVE-2003-1404 DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive informati… Botbr Mitigation only Fix from $1,9502003-12-31 MEDIUM 5.0 CVE-2003-1408 Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot. Domino Server No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1409 TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, … Topo Patch available Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1469EPSS 6% The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the… Coldfusion No fix yet Fix from $1,6002003-12-31 MEDIUM 5.8 CVE-2003-1481 CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack… Communigate Pro Patch available Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1486 Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quic… Phorum Patch available Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1517 cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error… Shopping Cart No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1526 PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which… Php Nuke No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1535 Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an e… Guestbook No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1540 WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentica… Wfchat Mitigation only Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1548EPSS 7% MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the … Myabracadaweb after 1.0.2 Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1550 XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals… Xoops after 2.0 Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1555 ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installa… Scozbook No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1559EPSS 16% Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, wh… Ie Mitigation only Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1560 Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive… Navigator Mitigation only Fix from $1,6002003-12-31