The Open Source Vulnerability Database

OSVDB is an independent and open source database created by and for the community.
Our goal is to provide accurate, detailed, current, and unbiased technical information.

Latest OSVDB Vulnerabilities

50361 Disclosed: 2008-06-10 Experts answer.php question_id Parameter SQL Injection
50360 Disclosed: 2008-03-29 Legion of the Bouncy Castle Crypto Package CMS Signature Bleichenbacher Weakness
50359 Disclosed: 2007-11-11 Legion of the Bouncy Castle Java Cryptography API Simple RSA CMS Signature Bleichenbacher Weakness
50358 Disclosed: 2007-11-09 Legion of the Bouncy Castle Provider Package Simple RSA CMS Signature Bleichenbacher Weakness
50357 Disclosed: 2006-10-03 Legion of the Bouncy Castle Crypto Package Public Exponents Bleichenbacher Weakness
50356 Disclosed: 2005-01-16 Legion of the Bouncy Castle Crypto Package Invalid Certificate Path Validation Weakness
50355 Disclosed: 2008-10-23 eCryptfs ecryptfs-utils ecryptfs-setup-pam-wrapped.sh Command Line Process Listing Cleartext Password Disclosure
50354 Disclosed: 2008-10-23 eCryptfs ecryptfs-utils ecryptfs-setup-confidential Command Line Process Listing Cleartext Password Disclosure
50353 Disclosed: 2008-10-23 eCryptfs ecryptfs-utils ecryptfs-setup-private Command Line Process Listing Cleartext Password Disclosure
50352 Disclosed: 2008-11-18 CUPS cgi-bin/admin.c Multiple RSS Subscription Function Policy Bypass CSRF

OSVDB News Feed

2008-11-20No Safety In Numbers
2008-11-10Looking for Volunteer Rails Developers!
2008-07-31OSVDB in Vegas.....
2008-07-14OSF To Maintain Attrition.org's Data Loss Database
2008-07-07Stop using Google, it's dangerous!
2008-07-07The Black Market Code Industry
2008-07-06VDBs Devolving?
2008-06-21OSVDB Featured in the Open Source Business Resource (OSBR)
2008-06-18Coffee makers are SCADA, right?!
2008-05-30Who's to blame? The hazard of "0-day".

Support OSVDB!

OSVDB needs your support! Donations get you enhanced access to the watch-list feature:

  • Watch unlimited products AND vendors, as opposed to just 10 products.
  • Receive notifications via RSS and email.

Pricing is in place for both individuals and organizations.

Visit the Support Page for details.

Sponsors

Sponsor

Member Highlight

Jericho


Top Viewed Vulnerabilities this week

18293 Views: 513 Belkin 54G Routers Admin Account Default Null Password
821 Views: 237 Linksys Router Default Password
40621 Views: 220 Simple PHP Blog (SPHPBlog) add_link.php link_id Variable CSRF
22297 Views: 177 VenomBoard add_post.php3 Multiple Variable SQL Injection
592 Views: 115 ZyXEL Multiple Routers Default Administrator Password
25257 Views: 106 Big Webmaster Guestbook addguest.cgi Multiple Field XSS
44643 Views: 105 Realtek HD Audio Codec Driver RTKVHDA.sys / RTKVHDA64.sys IOCTL Request Handling Overflow
49243 Views: 104 Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
18228 Views: 104 Asn Guestbook footer.php version Variable XSS
877 Views: 95 Multiple Web Server Dangerous HTTP Method TRACE

Top Blogged Vulnerabilities this Month

49243 Blogs: 113 Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
49060 Blogs: 11 Microsoft Windows Message Queuing Service RPC Request Handling Remote Code Execution
49061 Blogs: 10 Microsoft Windows Ancillary Function Driver (afd.sys) Local Privilege Escalation
49068 Blogs: 9 Microsoft Host Integration Server (HIS) SNA RPC Request Remote Overflow
49059 Blogs: 8 Microsoft IIS IPP Service Unspecified Remote Overflow
48239 Blogs: 7 ClamAV error path File Descriptor Leak Multiple Unspecified Issue
49076 Blogs: 6 Microsoft Excel BIFF File Malformed Object Handling Arbitrary Code Execution
49077 Blogs: 5 Microsoft Excel Calendar Object Validation VBA Performance Cache Processing Arbitrary Code Execution
49053 Blogs: 4 Microsoft Windows Virtual Address Descriptors (VAD) Local Privilege Escalation
47965 Blogs: 4 Microsoft Multiple Products GDI+ VML Gradient Size Handling Overflow

Blogs provided by Technorati

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use