Severity: MEDIUM

84400 CVEs found

CVE-2007-5626
5.5 MEDIUM

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows contex...

Published: 2007-10-23
Products: 1
Vendors:
bacula
CVE-2008-1567
5.5 MEDIUM

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive info...

Published: 2008-03-31
Products: 7
Vendors:
fedoraproject debian opensuse phpmyadmin
CVE-2008-2052
6.1 MEDIUM

Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.

Published: 2008-05-02
Products: 1
Vendors:
bitrix24
CVE-2008-1447
6.8 MEDIUM

The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementati...

Published: 2008-07-08
Products: 35
Vendors:
cisco redhat microsoft canonical debian +1 more
CVE-2008-2951
6.1 MEDIUM

Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possi...

Published: 2008-07-27
Products: 3
Vendors:
fedoraproject edgewall
CVE-2008-3275
5.5 MEDIUM

The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) di...

Published: 2008-08-12
Products: 8
Vendors:
linux debian canonical suse
CVE-2008-3775
4.4 MEDIUM

Folder Lock 5.9.5 and earlier uses weak encryption (ROT-25) for the password, which allows local administrators to obtain sensitive information by reading and decrypting the QualityControl\_pack regis...

Published: 2008-08-22
Products: 1
Vendors:
newsoftwares
CVE-2008-3281
6.5 MEDIUM

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consu...

Published: 2008-08-27
Products: 26
Vendors:
vmware redhat xmlsoft canonical fedoraproject +2 more
CVE-2007-6716
5.5 MEDIUM

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a cert...

Published: 2008-09-04
Products: 10
Vendors:
novell linux canonical suse debian +1 more
CVE-2008-4302
5.5 MEDIUM

fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was no...

Published: 2008-09-29
Products: 3
Vendors:
linux redhat debian
CVE-2008-4989
5.9 MEDIUM

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certi...

Published: 2008-11-13
Products: 13
Vendors:
gnu canonical suse fedoraproject debian +1 more
CVE-2009-0141
5.5 MEDIUM

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

Published: 2009-02-13
Products: 4
Vendors:
apple
CVE-2009-0935
5.5 MEDIUM

The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an in...

Published: 2009-03-18
Products: 3
Vendors:
linux
CVE-2009-1073
5.5 MEDIUM

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.

Published: 2009-03-31
Products: 2
Vendors:
debian
CVE-2009-1243
5.5 MEDIUM

net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes fr...

Published: 2009-04-06
Products: 1
Vendors:
linux
CVE-2009-1596
6.5 MEDIUM

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intende...

Published: 2009-05-11
Products: 1
Vendors:
igniterealtime
CVE-2009-1466
5.5 MEDIUM

Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.

Published: 2009-05-14
Products: 1
Vendors:
klinzmann
CVE-2009-0783
4.2 MEDIUM

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read o...

Published: 2009-06-05
Products: 3
Vendors:
apache
CVE-2009-1961
4.7 MEDIUM

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local ...

Published: 2009-06-08
Products: 15
Vendors:
linux canonical suse debian opensuse
CVE-2009-2213
6.5 MEDIUM

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Author...

Published: 2009-06-25
Products: 5
Vendors:
citrix