Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,558 CVEs tagged with CWE-200359 Critical, 2,065 High, 6,937 Medium, 1,193 Low, 4 Unrated.

CVE-2007-0011

Published Nov 5, 2007

The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-depende…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5774

Published Nov 1, 2007

index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4861

Published Oct 30, 2007

SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array paramet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5701

Published Oct 29, 2007

Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive in…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5335

Published Oct 24, 2007

Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5654

Published Oct 23, 2007

LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3850

Published Oct 23, 2007

The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical addres…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5379

Published Oct 19, 2007

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5549

Published Oct 18, 2007

Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5550

Published Oct 18, 2007

Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service", aka PSIRT-1255024833. NOTE:…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5554

Published Oct 18, 2007

Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the only disclosure is a vague pre…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5555

Published Oct 18, 2007

Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Inform…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5473

Published Oct 18, 2007

StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a tra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5470

Published Oct 16, 2007

Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5195

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5196

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5432

Published Oct 12, 2007

Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 10,376-10,400 of 10,558 CVEsPage 416 of 423