Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,634 CVEs tagged with CWE-200362 Critical, 2,093 High, 6,978 Medium, 1,196 Low, 5 Unrated.

CVE-2008-0863

Published Feb 21, 2008

BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potent…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0784

Published Feb 14, 2008

graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vector…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0736

Published Feb 13, 2008

admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccoun…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0041

Published Feb 12, 2008

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running P…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5333

Published Feb 12, 2008

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequence…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0593

Published Feb 9, 2008

Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0655

Published Feb 7, 2008

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

CVSS 8.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2008-0589

Published Feb 5, 2008

The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0395

Published Jan 23, 2008

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0367

Published Jan 19, 2008

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5958

Published Jan 18, 2008

X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different er…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0297

Published Jan 16, 2008

PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0249

Published Jan 12, 2008

PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0191

Published Jan 10, 2008

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0195

Published Jan 10, 2008

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5404

Published Jan 9, 2008

Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6660

Published Jan 4, 2008

2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6606

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6607

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/cus…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6536

Published Dec 27, 2007

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without veri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,401-10,425 of 10,634 CVEsPage 417 of 426