Total
7102 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0651 | 2 Apple, Google | 3 Safari, Webkit, Chrome | 2017-09-19 | 4.3 MEDIUM | N/A |
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document. | |||||
CVE-2010-1384 | 2 Apple, Microsoft | 6 Mac Os X, Mac Os X Server, Safari and 3 more | 2017-09-19 | 4.3 MEDIUM | N/A |
Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL. | |||||
CVE-2010-1796 | 2 Apple, Microsoft | 7 Mac Os X, Mac Os X Server, Safari and 4 more | 2017-09-19 | 2.6 LOW | N/A |
The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields. | |||||
CVE-2009-4145 | 1 Gnome | 1 Networkmanager | 2017-09-19 | 2.1 LOW | N/A |
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network. | |||||
CVE-2009-2475 | 1 Sun | 2 Java Se, Openjdk | 2017-09-19 | 7.8 HIGH | N/A |
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673. | |||||
CVE-2009-2711 | 2 Sun, X.org | 3 Opensolaris, Solaris, X11 | 2017-09-19 | 4.9 MEDIUM | N/A |
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276. | |||||
CVE-2009-3756 | 1 Kreotek | 1 Phpbms | 2017-09-19 | 5.0 MEDIUM | N/A |
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message. | |||||
CVE-2009-2332 | 1 Cms.tut.su | 1 Cms Chainuk | 2017-09-19 | 5.0 MEDIUM | N/A |
CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent folder name in the id parameter to admin/admin_delete.php, which reveals the installation path in an error message. | |||||
CVE-2009-3544 | 1 Xerver | 1 Xerver | 2017-09-19 | 5.0 MEDIUM | N/A |
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name. | |||||
CVE-2009-3646 | 1 Intervations | 1 Navicopa Web Server | 2017-09-19 | 5.0 MEDIUM | N/A |
InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name. | |||||
CVE-2009-3881 | 1 Sun | 2 Jre, Openjdk | 2017-09-19 | 7.5 HIGH | N/A |
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650. | |||||
CVE-2009-3987 | 1 Mozilla | 2 Firefox, Seamonkey | 2017-09-19 | 7.8 HIGH | N/A |
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects. | |||||
CVE-2009-3199 | 1 Uebimiau | 1 Uebimiau | 2017-09-19 | 5.0 MEDIUM | N/A |
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf. | |||||
CVE-2009-2329 | 1 Max Kervin | 1 Kervinet Forum | 2017-09-19 | 5.0 MEDIUM | N/A |
KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10) messages_list.php, (11) menu.php, (12) head.php, (13) forums_list.php, (14) forum_statistics.php, (15) forum_info.php, or (16) birthday.php in include_files/, which reveals the installation path in an error message. | |||||
CVE-2017-14240 | 1 Dolibarr | 1 Dolibarr | 2017-09-18 | 5.0 MEDIUM | 7.5 HIGH |
There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter. | |||||
CVE-2011-3177 | 1 Yast | 1 Yast2 | 2017-09-18 | 2.1 LOW | 7.8 HIGH |
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks. | |||||
CVE-2017-2550 | 1 Kubik-rubik | 1 Easy Joomla Backup | 2017-09-18 | 5.0 MEDIUM | 7.5 HIGH |
Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename. | |||||
CVE-2017-1162 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2017-09-16 | 5.0 MEDIUM | 7.5 HIGH |
IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957. | |||||
CVE-2017-0793 | 1 Google | 1 Android | 2017-09-15 | 7.1 HIGH | 5.5 MEDIUM |
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946. | |||||
CVE-2017-0779 | 1 Google | 1 Android | 2017-09-15 | 4.3 MEDIUM | 5.5 MEDIUM |
A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117. |