Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2003-0456
VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which l…
Visnetic Website
Patch available
MEDIUM 5.0
CVE-2002-1432EPSS 8%
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly …
A Cart
Patch available
MEDIUM 5.0
CVE-2003-0001EPSS 73%
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information …
FreeBSD
Mitigation only
MEDIUM 5.0
CVE-2002-1717EPSS 16%
Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /…
Internet Information Services
Mitigation only
MEDIUM 5.0
CVE-2002-1718EPSS 14%
Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim…
Internet Information Services
Mitigation only
MEDIUM 5.0
CVE-2002-2276
Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the …
Ultimate Php Board
No fix yet
MEDIUM 5.0
CVE-2002-2288
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that doe…
Site Server
Patch available
MEDIUM 5.0
CVE-2002-2289
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
Badblue
No fix yet
HIGH 7.8
CVE-2002-2317
Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumpt…
Velociraptor
Patch available
MEDIUM 5.0
CVE-2002-2342
Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient …
Bannermatic
Mitigation only
MEDIUM 5.0
CVE-2002-2346
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers…
Phpbb
Mitigation only
MEDIUM 5.0
CVE-2002-2349
phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.
Phpbbmod
No fix yet
MEDIUM 5.0
CVE-2002-2369
Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.
Liteserve
Patch available
MEDIUM 6.4
CVE-2002-2380EPSS 11%
NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u…
Network Firmware
Mitigation only
MEDIUM 5.0
CVE-2002-2410
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists o…
Open Webmail
No fix yet
MEDIUM 5.0
CVE-2002-0419EPSS 38%
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks …
Internet Information Server
No fix yet
MEDIUM 6.4
CVE-2002-0812
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default S…
Compaq Wl310 Firmware
Mitigation only
MEDIUM 5.0
CVE-2002-0596
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty…
Reporting Center
Patch available
MEDIUM 5.0
CVE-2000-0876
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message…
Wftpd
Mitigation only
MEDIUM 5.0
CVE-2000-0588EPSS 7%
SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose content…
Sawmill
No fix yet
MEDIUM 5.0
CVE-1999-1462
Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attackers to read portions of arbitrary files.
Big Brother
Patch available
MEDIUM 5.0
CVE-1999-0605
An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.
Merchant Order Form
No fix yet
MEDIUM 5.0
CVE-1999-0606
An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.
Ezmall
Mitigation only
MEDIUM 5.0
CVE-1999-0348EPSS 11%
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
Internet Information Server
Mitigation only
MEDIUM 5.0
CVE-1999-0453
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
Router
Mitigation only
HIGH 7.3
CVE-1999-0632
The RPC portmapper service is running.
Mitigation only
HIGH 7.3
CVE-1999-0059
IRIX fam service allows an attacker to obtain a list of all files on the server.
Irix
Mitigation only
CRITICAL 9.1
CVE-1999-0511EPSS 7%
IP forwarding is enabled on a machine which is not a router or firewall.
Windows 2000
Mitigation only
MEDIUM 5.9
CVE-1999-0517EPSS 27%
An SNMP community name is the default (e.g. public), null, or missing.
Hp Ux
Mitigation only