Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,598 CVEs tagged with CWE-200359 Critical, 2,083 High, 6,958 Medium, 1,194 Low, 4 Unrated.

CVE-2007-5379

Published Oct 19, 2007

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5549

Published Oct 18, 2007

Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5550

Published Oct 18, 2007

Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service", aka PSIRT-1255024833. NOTE:…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5554

Published Oct 18, 2007

Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the only disclosure is a vague pre…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5555

Published Oct 18, 2007

Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Inform…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5473

Published Oct 18, 2007

StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a tra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5470

Published Oct 16, 2007

Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5195

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5196

Published Oct 14, 2007

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5432

Published Oct 12, 2007

Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5420

Published Oct 12, 2007

The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might al…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5264

Published Oct 8, 2007

Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5201

Published Oct 4, 2007

The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the proc…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5172

Published Oct 1, 2007

Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the result…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5129

Published Sep 27, 2007

SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5034

Published Sep 21, 2007

ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4991

Published Sep 21, 2007

The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5028

Published Sep 21, 2007

Dibbler 0.6.0 on Linux uses weak world-writable permissions for unspecified files in /var/lib/dibbler, which has unknown impact and local attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5022

Published Sep 21, 2007

Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "serve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,426-10,450 of 10,598 CVEsPage 418 of 424