Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2009-2422
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_reques…
Ruby On Rails
2.3.3 / 10.6.3+
CRITICAL 9.8
CVE-2009-2382EPSS 6%
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin c…
Phpmyblockchecker
No fix yet
HIGH 7.5
CVE-2009-2328
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitra…
Kervinet Forum
after 1.1
HIGH 7.8
CVE-2009-2257EPSS 7%
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to…
Dg632
No fix yet
MEDIUM 6.8
CVE-2009-2255EPSS 31%
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exe…
Zen Cart
after 1.3.8a
HIGH 7.5
CVE-2009-2233
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by set…
Gallery Search Engine
No fix yet
HIGH 7.5
CVE-2009-2231
MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.
Midas
No fix yet
CRITICAL 9.8
CVE-2009-2168EPSS 12%
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials ar…
7ammel
after 1.0.1
MEDIUM 6.4
CVE-2009-2159
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and downloa…
Torrenttrader Classic
No fix yet
HIGH 7.5
CVE-2009-2117
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a v…
Phportal
No fix yet
MEDIUM 6.8
CVE-2009-1390
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the …
Mutt
Patch available
MEDIUM 6.8
CVE-2009-2058
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p…
Safari
after 3.2.2
MEDIUM 6.8
CVE-2009-2059
Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from …
Opera Browser
after 9.22
MEDIUM 5.8
CVE-2009-2060
src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided…
Chrome
after 1.0.154.52
MEDIUM 6.8
CVE-2009-2062
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execut…
Safari
after 3.2.1
MEDIUM 6.8
CVE-2009-2063
Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to exe…
Opera Browser
after 9.24
MEDIUM 6.8
CVE-2009-2064
Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which a…
Internet Explorer
after 8
MEDIUM 6.8
CVE-2009-2065
Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m…
Firefox
after 3.0.9
MEDIUM 6.8
CVE-2009-2066
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute ar…
Safari
after 3.2.1
MEDIUM 6.8
CVE-2009-2067
Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary…
Opera Browser
after 9.22
MEDIUM 5.8
CVE-2009-2068
Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute a…
Opera
Mitigation only
MEDIUM 5.8
CVE-2009-2069
Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which a…
Ie
Mitigation only
MEDIUM 6.8
CVE-2009-2070
Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attacke…
Opera Browser
Mitigation only
MEDIUM 6.8
CVE-2009-2071
Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows…
Chrome
after 1.0.154.52
MEDIUM 5.4
CVE-2009-2072
Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to s…
Safari
after 3.2.1
MEDIUM 5.8
CVE-2009-2057
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT respon…
Ie
No fix yet
MEDIUM 6.8
CVE-2009-1836
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume…
Firefox
after 3.0.10
HIGH 7.5
CVE-2009-2040
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative …
Grestul
No fix yet
HIGH 7.5
CVE-2009-1122EPSS 98%
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote atta…
Internet Information Services
Patch available
HIGH 7.5
CVE-2009-1535EPSS 98%
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, …
Internet Information Services
Patch available