Vulnerabilities (CVE)

Filtered by CWE-200
Total 11011 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-5101 1 Pentaho 1 Bi Server 2026-06-16 5.0 MEDIUM N/A
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
CVE-2009-5100 1 Pentaho 1 Bi Server 2026-06-16 2.1 LOW N/A
Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.
CVE-2009-5045 2 Debian, Eclipse 2 Debian Linux, Jetty 2026-06-16 5.0 MEDIUM 7.5 HIGH
Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5035 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.3 MEDIUM N/A
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.
CVE-2009-5033 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.0 MEDIUM N/A
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.
CVE-2009-4961 1 Lanai-core 1 Lanai-core 2026-06-16 5.0 MEDIUM N/A
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
CVE-2009-4951 2 Hans Olthoff, Typo3 2 Alternet Csa Out, Typo3 2026-06-16 5.0 MEDIUM N/A
Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
CVE-2009-4943 1 Impactsoftcompany 1 Adpeeps 2026-06-16 5.0 MEDIUM N/A
index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an invalid uid parameter, which reveals the installation path in an error message; or (2) an adminlogin action with a crafted uid parameter, which reveals the version number.
CVE-2009-4844 1 Toutvirtual 1 Virtualiq 2026-06-16 5.0 MEDIUM N/A
ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive Tomcat information via a direct request.
CVE-2009-4812 1 Wolfram 1 Webmathematica 2026-06-16 5.0 MEDIUM N/A
Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message.
CVE-2009-4630 1 Mozilla 3 Firefox, Seamonkey, Thunderbird 2026-06-16 5.0 MEDIUM N/A
Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML documents, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests. NOTE: the vendor disputes the significance of this issue, stating "I don't think we necessarily need to worry about that case."
CVE-2009-4629 1 Mozilla 2 Seamonkey, Thunderbird 2026-06-16 5.0 MEDIUM N/A
Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests, as demonstrated by DNS requests triggered by reading text/plain e-mail messages in Thunderbird.
CVE-2009-4609 1 Mortbay 1 Jetty 2026-06-16 5.0 MEDIUM N/A
The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.
CVE-2009-4535 1 Valenok 1 Mongoose 2026-06-16 5.0 MEDIUM N/A
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
CVE-2009-4533 2 Drupal, Nathan Haug 2 Drupal, Webform 2026-06-16 5.0 MEDIUM N/A
The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which allows remote attackers to read session variables via unspecified vectors.
CVE-2009-4531 1 Jasper 1 Httpdx 2026-06-16 5.0 MEDIUM N/A
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.
CVE-2009-4530 1 Sergey Lyubka 1 Mongoose 2026-06-16 5.0 MEDIUM N/A
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
CVE-2009-4529 1 Intervations 1 Navicopa Web Server 2026-06-16 5.0 MEDIUM N/A
InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space character in a URI, as demonstrated by /index.html%20 and /index.php%20 URIs.
CVE-2009-4511 1 Vsecurity 1 Tandberg Video Communication Server 2026-06-16 4.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.
CVE-2009-4466 1 Deluxebb 1 Deluxebb 2026-06-16 5.0 MEDIUM N/A
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resultant from improperly controlled computation in tools.php that leads to a denial of service (CPU or memory consumption).