Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,635 CVEs tagged with CWE-200362 Critical, 2,094 High, 6,979 Medium, 1,196 Low, 4 Unrated.

CVE-2008-2723

Published Jun 16, 2008

embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2715

Published Jun 16, 2008

Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as patterns.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2681

Published Jun 12, 2008

Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2517

Published Jun 3, 2008

The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the proc…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1578

Published Jun 2, 2008

The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing th…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1579

Published Jun 2, 2008

Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2004

Published May 12, 2008

The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifyin…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2159

Published May 12, 2008

Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sen…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2049

Published May 1, 2008

The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2028

Published Apr 30, 2008

miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew ac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2027

Published Apr 30, 2008

Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such as Mozilla Firefox, allows re…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2018

Published Apr 30, 2008

The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1924

Published Apr 23, 2008

Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1155

Published Apr 16, 2008

Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1752

Published Apr 11, 2008

ezRADIUS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for (1) con…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1717

Published Apr 9, 2008

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1618

Published Apr 7, 2008

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1014

Published Apr 4, 2008

Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1680

Published Apr 4, 2008

PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gp…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1598

Published Mar 31, 2008

The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1557

Published Mar 31, 2008

BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1156

Published Mar 27, 2008

Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,351-10,375 of 10,635 CVEsPage 415 of 426