Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,347 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 4 Unrated.

CVE-2008-1330

Published Mar 18, 2008

Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1318

Published Mar 13, 2008

Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback parameter in an API call for JavaSc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1288

Published Mar 11, 2008

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1270

Published Mar 10, 2008

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1252

Published Mar 10, 2008

b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading the pwd field in the HTML sourc…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1181

Published Mar 6, 2008

Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1166

Published Mar 5, 2008

Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1111

Published Mar 4, 2008

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive informati…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1135

Published Mar 4, 2008

OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0978

Published Feb 25, 2008

Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain sensitive information via a pac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0938

Published Feb 25, 2008

Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive k…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0863

Published Feb 21, 2008

BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potent…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0784

Published Feb 14, 2008

graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vector…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0736

Published Feb 13, 2008

admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccoun…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0041

Published Feb 12, 2008

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running P…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5333

Published Feb 12, 2008

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequence…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0593

Published Feb 9, 2008

Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0655

Published Feb 7, 2008

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

CVSS 8.8 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2008-0589

Published Feb 5, 2008

The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 10,101-10,125 of 10,347 CVEsPage 405 of 414