Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,598 CVEs tagged with CWE-200359 Critical, 2,083 High, 6,958 Medium, 1,194 Low, 4 Unrated.

CVE-2007-4669

Published Sep 4, 2007

The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3382

Published Aug 14, 2007

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3385

Published Aug 14, 2007

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which migh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2402

Published Jul 15, 2007

QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3656

Published Jul 10, 2007

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3074

Published Jun 6, 2007

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2780

Published May 21, 2007

PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2748

Published May 17, 2007

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than C…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2552

Published May 9, 2007

The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS fee…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2479

Published May 3, 2007

Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which g…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2379

Published Apr 30, 2007

The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web pag…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2353

Published Apr 30, 2007

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception mess…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2253

Published Apr 25, 2007

Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.ph…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2022

Published Apr 13, 2007

Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes),…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1562

Published Mar 21, 2007

The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxie…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1563

Published Mar 21, 2007

The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obt…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1564

Published Mar 21, 2007

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive informat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1237

Published Mar 3, 2007

sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,451-10,475 of 10,598 CVEsPage 419 of 424