The Open Source Vulnerability Database

OSVDB is an independent and open source database created by and for the community.
Our goal is to provide accurate, detailed, current, and unbiased technical information.

Latest OSVDB Vulnerabilities

45220 Disclosed: 2008-05-14 Cisco Unified Presence Engine Service Malformed IP Packet Processing Remote DoS (CSCsh20972)
45219 Disclosed: 2008-05-14 Cisco Unified Presence Engine Service Malformed IP Packet Processing Remote DoS (CSCsh50164)
45218 Disclosed: 2008-05-09 Microsoft Outlook Web Access Cache-Control Directive Information Caching Persistence
45217 Disclosed: 2008-04-25 rootpw Plugin for rPath Appliance Platform Agent Crafted URL Root Password Reset CSRF
45216 Disclosed: 2008-05-14 Cisco Unified Presence SIP Proxy Service TCP Port Scan Remote DoS
45215 Disclosed: 2008-04-25 rootpw Plugin for rPath Appliance Platform Agent Request Revalidation Handling Local Privilege Escalation
45214 Disclosed: 2008-05-15 Mantis Unspecified CSRF
45213 Disclosed: 2008-05-14 Feedback and Rating Script detail.php listingid Variable SQL Injection
45212 Disclosed: 2008-05-14 Freelance Auction Script browseproject.php pid Variable SQL Injection
45211 Disclosed: 2008-05-12 AJ Article featured_article.php artid Variable SQL Injection

OSVDB News Feed

2008-05-16Layered Technologies Continued Support of OSVDB by Jkouns
2008-04-22Three Projects For SoC 2008 by Jkouns
2008-04-15OSVDB - Apr 14 Code Push by Jericho
2008-04-08Dr. Jekyll and Mr. Hide (Sun & Disclosure) by Jericho
2008-04-03Vulnerability counts and OSVDB advocacy by Jericho
2008-03-29Still time to submit an application for SoC 2008! by Jkouns
2008-03-25OSVDB - Mar 25 Code Push by Jericho
2008-03-24The purpose of tracking numbers.. (IBM) by Jericho
2008-03-18OSVDB Selected for Google Summer of Code 2008 by Jkouns
2008-03-16“high price bug brokering market just isn’t viable” by Jericho

Support OSVDB!

OSVDB needs your support! Donations get you enhanced access to the watch-list feature:

  • Watch unlimited products AND vendors, as opposed to just 10 products.
  • Receive notifications via RSS and email.

Pricing is in place for both individuals and organizations.

Visit the Support Page for details.

Sponsors

Sponsor

Member Highlight

Jkouns


Top Viewed Vulnerabilities this week

18293 Views: 481 Belkin 54G Routers Admin Account Default Null Password
40621 Views: 355 Simple PHP Blog (SPHPBlog) add_link.php link_id Variable CSRF
821 Views: 322 Linksys Router Default Password
28946 Views: 243 Microsoft IE Vector Markup Language (VML) Arbitrary Code Execution
4030 Views: 202 TCP/IP Sequence Prediction Blind Reset Spoofing DoS
592 Views: 160 ZyXEL Multiple Routers Default Administrator Password
32096 Views: 157 Snort Rule Predicate Rule Matching Backtrack DoS
44880 Views: 155 Microsoft Windows msjet40.dll MDB File Handling Overflow
44875 Views: 133 PostcardMentor step1.asp cat_fldAuto Variable SQL Injection
877 Views: 125 Multiple Web Server Dangerous HTTP Method TRACE

Top Blogged Vulnerabilities this Month

45029 Blogs: 20 OpenSSL on Debian/Ubuntu Linux Predictable Random Number Generator (RNG) Cryptographic Key Generation Weakness
43980 Blogs: 14 Apple Safari WebKit (JavaScriptCore/pcre/pcre_compile.cpp) PCRE Nested Repetition Count Overflow
44623 Blogs: 13 WordPress Unspecified XSS
45031 Blogs: 13 Microsoft Office RTF File Handling Object Parsing Arbitrary Code Execution
44880 Blogs: 13 Microsoft Windows msjet40.dll MDB File Handling Overflow
43870 Blogs: 11 Mozilla Multiple Products JSOP_NEG js_NewNumberValue SAVE_SP_AND_PC Unspecified DoS
44205 Blogs: 11 Microsoft IE Data Stream Handling Memory Corruption
44213 Blogs: 11 Microsoft Windows GDI (gdi32.dll) EMF File Handling Multiple Overflows
44652 Blogs: 9 Microsoft HeartbeatCtl HRTBEAT.OCX ActiveX Unspecified Method Host Argument Overflow
44364 Blogs: 8 libpng Zero-length Unknown Chunk Processing Uninitialized Memory Access

Blogs provided by Technorati

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use