Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,347 CVEs tagged with CWE-200345 Critical, 2,000 High, 6,835 Medium, 1,163 Low, 4 Unrated.

CVE-2008-0395

Published Jan 23, 2008

Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0367

Published Jan 19, 2008

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5958

Published Jan 18, 2008

X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different er…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0297

Published Jan 16, 2008

PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0249

Published Jan 12, 2008

PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0191

Published Jan 10, 2008

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0195

Published Jan 10, 2008

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5404

Published Jan 9, 2008

Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6660

Published Jan 4, 2008

2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6606

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6607

Published Dec 31, 2007

OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/cus…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6536

Published Dec 27, 2007

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without veri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6524

Published Dec 24, 2007

Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6512

Published Dec 21, 2007

PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6513

Published Dec 21, 2007

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6514

Published Dec 21, 2007

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6476

Published Dec 20, 2007

GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6502

Published Dec 20, 2007

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6283

Published Dec 18, 2007

Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as…

CVSS 4.9 · Medium

CVE-2007-6417

Published Dec 18, 2007

The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances related to tmpfs, which might all…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6418

Published Dec 18, 2007

The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6405

Published Dec 17, 2007

Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6408

Published Dec 17, 2007

IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6249

Published Dec 15, 2007

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 10,126-10,150 of 10,347 CVEsPage 406 of 414