VYPR

CVEs

347,154 total · page 5865 of 6,944

  • CVE-2012-5651Jan 3, 2013
    risk 0.00cvss epss 0.03

    Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

  • CVE-2012-4545Jan 3, 2013
    risk 0.00cvss epss 0.02

    The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the…

  • CVE-2012-2379Jan 3, 2013
    risk 0.00cvss epss 0.04

    Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

  • CVE-2013-0721Jan 2, 2013
    risk 0.00cvss epss 0.02

    wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

  • CVE-2012-6472Jan 2, 2013
    risk 0.00cvss epss 0.00

    Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache file, (2) password file, or (3) configuration file, or (4) possibly gain privileges by modifying or overwriting a…

  • CVE-2012-6471Jan 2, 2013
    risk 0.00cvss epss 0.01

    Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

  • CVE-2012-6470Jan 2, 2013
    risk 0.04cvss epss 0.08

    Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.

  • CVE-2012-6469Jan 2, 2013
    risk 0.00cvss epss 0.01

    Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.

  • CVE-2012-6468Jan 2, 2013
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long HTTP response.

  • CVE-2012-6467Jan 2, 2013
    risk 0.00cvss epss 0.01

    Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.

  • CVE-2012-6466Jan 2, 2013
    risk 0.00cvss epss 0.02

    Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas.

  • CVE-2012-6465Jan 2, 2013
    risk 0.00cvss epss 0.04

    Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.

  • CVE-2012-6464Jan 2, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.

  • CVE-2012-6463Jan 2, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs.

  • CVE-2012-6462Jan 2, 2013
    risk 0.00cvss epss 0.02

    Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.

  • CVE-2012-6461Jan 2, 2013
    risk 0.00cvss epss 0.01

    The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service.

  • CVE-2012-6460Jan 2, 2013
    risk 0.00cvss epss 0.02

    Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger downloading and execution of arbitrary programs, via a crafted web site.

  • CVE-2012-6459Jan 1, 2013
    risk 0.00cvss epss 0.01

    ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets.

  • CVE-2012-6426Jan 1, 2013
    risk 0.00cvss epss 0.02

    LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.

  • CVE-2012-6084Jan 1, 2013
    risk 0.00cvss epss 0.03

    modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed…

  • CVE-2012-5769Jan 1, 2013
    risk 0.00cvss epss 0.01

    IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in…

  • CVE-2012-5573Jan 1, 2013
    risk 0.00cvss epss 0.03

    The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass…

  • CVE-2012-4970Jan 1, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-6371Dec 31, 2012
    risk 0.00cvss epss 0.01

    The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading broadcast packets, a different vulnerability than…

  • CVE-2011-5251Dec 31, 2012
    risk 0.00cvss epss 0.02

    Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.

  • CVE-2012-6453Dec 31, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a crafted feed.

  • CVE-2012-6339Dec 31, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and…

  • CVE-2012-6337Dec 31, 2012
    risk 0.00cvss epss 0.02

    The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.

  • CVE-2012-6336Dec 31, 2012
    risk 0.00cvss epss 0.00

    The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

  • CVE-2012-6335Dec 31, 2012
    risk 0.00cvss epss 0.00

    The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

  • CVE-2012-6334Dec 31, 2012
    risk 0.00cvss epss 0.01

    The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

  • CVE-2012-5642Dec 31, 2012
    risk 0.00cvss epss 0.03

    server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.

  • CVE-2012-4688Dec 31, 2012
    risk 0.00cvss epss 0.02

    The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.

  • CVE-2012-4792HigKEVDec 30, 2012
    risk 0.79cvss 8.8epss 0.79

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and…

  • CVE-2012-6369Dec 28, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting…

  • CVE-2012-5445Dec 28, 2012
    risk 0.00cvss epss 0.00

    The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory…

  • CVE-2012-4932Dec 28, 2012
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the…

  • CVE-2012-4528Dec 28, 2012
    risk 0.04cvss epss 0.13

    The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

  • CVE-2012-3873Dec 28, 2012
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5)…

  • CVE-2012-3872Dec 28, 2012
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.

  • CVE-2012-3871Dec 28, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

  • CVE-2012-3870Dec 28, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or (2) description parameter.

  • CVE-2012-0741Dec 28, 2012
    risk 0.00cvss epss 0.01

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

  • CVE-2012-0738Dec 28, 2012
    risk 0.00cvss epss 0.01

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

  • CVE-2012-6432Dec 27, 2012
    risk 0.00cvss epss 0.01

    Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

  • CVE-2012-6431Dec 27, 2012
    risk 0.00cvss epss 0.02

    Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

  • CVE-2012-5868Dec 27, 2012
    risk 0.00cvss epss 0.02

    WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

  • CVE-2012-5532Dec 27, 2012
    risk 0.00cvss epss 0.00

    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an…

  • CVE-2012-2669Dec 27, 2012
    risk 0.00cvss epss 0.00

    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.

  • CVE-2012-6314Dec 26, 2012
    risk 0.00cvss epss 0.02

    Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.