Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

585 CVEs tagged with CWE-20927 Critical, 75 High, 401 Medium, 81 Low, 1 Unrated.

CVE-2018-2379

Published Feb 14, 2018

In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-7551

Published Aug 16, 2017

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1370

Published Jul 31, 2017

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator confi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7945

Published Apr 29, 2017

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-0885

Published Apr 5, 2017

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7331

Published Feb 26, 2014

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet host…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
56.0
KEV listed

CVE-2000-1191

Published Aug 31, 2001

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-585 of 585 CVEsPage 24 of 24