Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2009-1084
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth…
Java System Identity Manager
Patch available
MEDIUM 6.2
CVE-2008-6514
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using …
Compiz Fusion
Patch available
MEDIUM 5.0
CVE-2009-1051
FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…
Fubarforum
after 1.6
MEDIUM 5.0
CVE-2009-1052
FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…
Fireant
after 1.3
MEDIUM 5.0
CVE-2009-1053
chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …
Chaozzdb
after 1.2
MEDIUM 5.0
CVE-2008-6506
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknow…
Phpbb
after 3.0.3
MEDIUM 5.0
CVE-2008-6493
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
Easy Content Management Publishing
No fix yet
MEDIUM 5.0
CVE-2008-6494
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat…
Asp User Engine.net
No fix yet
HIGH 8.8
CVE-2008-6496
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows rem…
Expert Pdf Editorx
No fix yet
HIGH 7.6
CVE-2009-0941
The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes i…
8100c Digital Sender
Mitigation only
MEDIUM 6.8
CVE-2009-0872
The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combinati…
Opensolaris
Patch available
MEDIUM 6.8
CVE-2009-0873
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security …
Opensolaris
Patch available
MEDIUM 5.0
CVE-2009-0866
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database…
Phnews
No fix yet
MEDIUM 5.0
CVE-2009-0760
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …
Team Board
No fix yet
MEDIUM 5.0
CVE-2009-0767
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contai…
Kipper
No fix yet
MEDIUM 6.4
CVE-2008-6399
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack …
Dotnetnuke
Mitigation only
MEDIUM 5.0
CVE-2009-0826
BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file cont…
Bloghelper
No fix yet
MEDIUM 5.0
CVE-2009-0827
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containin…
Pollhelper
No fix yet
MEDIUM 5.0
CVE-2009-0828
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informati…
Quotebook
No fix yet
HIGH 9.3
CVE-2009-0367EPSS 11%
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a white…
Wesnoth
Patch available
MEDIUM 6.2
CVE-2009-0578
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to cha…
Ubuntu Linux
Mitigation only
MEDIUM 6.5
CVE-2009-0806
Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.
Opengoo
after 1.2
HIGH 7.5
CVE-2009-0807
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
Zfeeder
No fix yet
MEDIUM 5.4
CVE-2009-0801
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to by…
Squid Web Proxy Cache
Mitigation only
MEDIUM 5.4
CVE-2009-0802
Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacker…
Wingate
Mitigation only
MEDIUM 5.4
CVE-2009-0803
SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, u…
Networkguardian
Mitigation only
MEDIUM 5.4
CVE-2009-0804
Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacke…
Ziproxy
Mitigation only
MEDIUM 5.0
CVE-2008-6374
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote a…
Mailinglistpro
No fix yet
MEDIUM 5.0
CVE-2008-6375
JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file v…
Jbook
No fix yet
MEDIUM 5.0
CVE-2008-6382
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data…
Aspportal
No fix yet