Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,350 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 7 Unrated.

CVE-2008-4820

Published Nov 10, 2008

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4808

Published Oct 31, 2008

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4695

Published Oct 23, 2008

Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launc…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4721

Published Oct 23, 2008

PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4693

Published Oct 22, 2008

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive informat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4688

Published Oct 22, 2008

core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4638

Published Oct 21, 2008

qioadmin in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, allows local users to read arbitrary…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3248

Published Oct 21, 2008

qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem bloc…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4635

Published Oct 21, 2008

Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown ve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4593

Published Oct 17, 2008

Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by p…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4412

Published Oct 17, 2008

Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4491

Published Oct 8, 2008

Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server own…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3060

Published Oct 8, 2008

V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4445

Published Oct 6, 2008

The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH ex…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4360

Published Oct 3, 2008

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4359

Published Oct 3, 2008

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4199

Published Sep 27, 2008

Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow remote attackers to determine the validity of local filena…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4069

Published Sep 24, 2008

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4207

Published Sep 24, 2008

Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4183

Published Sep 23, 2008

IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a bac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,976-10,000 of 10,350 CVEsPage 400 of 414