Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0653 | 1 Opera | 1 Opera Browser | 2010-09-20 | 4.3 MEDIUM | N/A |
Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document. | |||||
CVE-2010-3018 | 1 Rsa | 1 Access Manager Server | 2010-09-09 | 4.3 MEDIUM | N/A |
RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2010-3244 | 1 Blackboard | 1 Transact Suite | 2010-09-08 | 4.6 MEDIUM | N/A |
BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml field value, which allows local users to discover the database password via a modified connection.xml file that contains an encrypted password in the <Server> field. | |||||
CVE-2010-2758 | 1 Mozilla | 1 Bugzilla | 2010-09-07 | 5.0 MEDIUM | N/A |
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page. | |||||
CVE-2010-1800 | 1 Apple | 3 Cfnetwork, Mac Os X, Mac Os X Server | 2010-08-25 | 5.0 MEDIUM | N/A |
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses. | |||||
CVE-2010-2982 | 1 Cisco | 1 Unified Wireless Network Solution Software | 2010-08-10 | 7.1 HIGH | N/A |
Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to discover a group password via a series of SNMP requests, as demonstrated by an SNMP walk, aka Bug ID CSCtb74037. | |||||
CVE-2010-2975 | 1 Cisco | 1 Unified Wireless Network Solution Software | 2010-08-10 | 2.1 LOW | N/A |
Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544. | |||||
CVE-2009-4951 | 2 Hans Olthoff, Typo3 | 2 Alternet Csa Out, Typo3 | 2010-07-22 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |||||
CVE-2010-2333 | 1 Litespeedtech | 1 Litespeed Web Server | 2010-07-12 | 5.0 MEDIUM | N/A |
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension. | |||||
CVE-2009-4326 | 1 Ibm | 1 Db2 | 2010-06-28 | 4.3 MEDIUM | N/A |
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value. | |||||
CVE-2009-4333 | 1 Ibm | 1 Db2 | 2010-06-28 | 7.5 HIGH | N/A |
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command. | |||||
CVE-2006-6998 | 1 Headstart Solutions | 1 Deskpro | 2010-06-28 | 5.0 MEDIUM | N/A |
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function. | |||||
CVE-2010-2323 | 1 Ibm | 2 Websphere Application Server, Zos | 2010-06-24 | 5.0 MEDIUM | N/A |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT. | |||||
CVE-2010-2336 | 1 Yamamah | 1 Yamamah | 2010-06-21 | 5.0 MEDIUM | N/A |
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter. | |||||
CVE-2010-0523 | 1 Apple | 1 Mac Os X Server | 2010-06-20 | 5.0 MEDIUM | N/A |
Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet. | |||||
CVE-2010-2326 | 1 Ibm | 1 Websphere Application Server | 2010-06-20 | 4.3 MEDIUM | N/A |
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file. | |||||
CVE-2009-2260 | 1 Stardict | 1 Stardict | 2010-06-13 | 5.0 MEDIUM | N/A |
stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2010-1294 | 1 Adobe | 1 Coldfusion | 2010-05-13 | 2.1 LOW | N/A |
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors. | |||||
CVE-2010-1457 | 1 Gnustep | 1 Gnustep Base | 2010-05-12 | 4.9 MEDIUM | N/A |
Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message. | |||||
CVE-2009-4812 | 1 Wolfram | 1 Webmathematica | 2010-04-27 | 5.0 MEDIUM | N/A |
Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message. |