VYPR

CVEs

347,154 total · page 5871 of 6,944

  • CVE-2012-5174Nov 30, 2012
    risk 0.00cvss epss 0.03

    The KYOCERA AH-K3001V, AH-K3002V, WX300K, WX310K, WX320K, and WX320KR devices allow remote attackers to cause a denial of service (persistent reboot) via an e-mail message in an invalid format.

  • CVE-2012-4222Nov 30, 2012
    risk 0.00cvss epss 0.01

    drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) via an application that uses crafted arguments in a local kgsl_ioctl call.

  • CVE-2012-4221Nov 30, 2012
    risk 0.00cvss epss 0.02

    Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service via an application that uses crafted arguments in a local…

  • CVE-2012-4220Nov 30, 2012
    risk 0.00cvss epss 0.03

    diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments…

  • CVE-2012-5530Nov 29, 2012
    risk 0.00cvss epss 0.00

    The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

  • CVE-2012-4841Nov 29, 2012
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause a denial of service (resource consumption) via unknown vectors.

  • CVE-2012-3271Nov 29, 2012
    risk 0.00cvss epss 0.05

    Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors.

  • CVE-2012-6051Nov 28, 2012
    risk 0.00cvss epss 0.01

    Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as…

  • CVE-2012-5373Nov 28, 2012
    risk 0.00cvss epss 0.02

    Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an…

  • CVE-2012-5372Nov 28, 2012
    risk 0.00cvss epss 0.02

    Rubinius computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated…

  • CVE-2012-5371Nov 28, 2012
    risk 0.00cvss epss 0.03

    Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an…

  • CVE-2012-5370Nov 28, 2012
    risk 0.00cvss epss 0.02

    JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by…

  • CVE-2012-2739Nov 28, 2012
    risk 0.00cvss epss 0.03

    Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via…

  • CVE-2012-5136Nov 28, 2012
    risk 0.00cvss epss 0.01

    Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.

  • CVE-2012-5135Nov 28, 2012
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

  • CVE-2012-5134Nov 28, 2012
    risk 0.00cvss epss 0.04

    Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted…

  • CVE-2012-5133Nov 28, 2012
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.

  • CVE-2012-5132Nov 28, 2012
    risk 0.00cvss epss 0.01

    Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

  • CVE-2012-5131Nov 28, 2012
    risk 0.00cvss epss 0.01

    Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-5130Nov 28, 2012
    risk 0.00cvss epss 0.01

    Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2012-4964Nov 28, 2012
    risk 0.01cvss epss 0.08

    The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administrative access via an SNMP request.

  • CVE-2012-4615Nov 27, 2012
    risk 0.00cvss epss 0.00

    EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2012-4614Nov 27, 2012
    risk 0.00cvss epss 0.02

    The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.

  • CVE-2012-4611Nov 27, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-6050Nov 27, 2012
    risk 0.04cvss epss 0.09

    The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

  • CVE-2012-6049Nov 27, 2012
    risk 0.00cvss epss 0.01

    Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

  • CVE-2012-6048Nov 27, 2012
    risk 0.03cvss epss 0.02

    Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.

  • CVE-2012-6047Nov 27, 2012
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to index.php.

  • CVE-2012-6046Nov 27, 2012
    risk 0.03cvss epss 0.04

    Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.

  • CVE-2012-6045Nov 27, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2010-5286Nov 26, 2012
    risk 0.04cvss epss 0.11

    Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-5285Nov 26, 2012
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.

  • CVE-2010-5284Nov 26, 2012
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3)…

  • CVE-2010-5283Nov 26, 2012
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permissions.

  • CVE-2010-5282Nov 26, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx,…

  • CVE-2010-5281Nov 26, 2012
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third…

  • CVE-2010-5280Nov 26, 2012
    risk 0.03cvss epss 0.05

    Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to…

  • CVE-2012-6044Nov 26, 2012
    risk 0.03cvss epss 0.02

    M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.

  • CVE-2012-6043Nov 26, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

  • CVE-2012-6042Nov 26, 2012
    risk 0.03cvss epss 0.02

    GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.

  • CVE-2012-6041Nov 26, 2012
    risk 0.03cvss epss 0.04

    Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.

  • CVE-2012-6040Nov 26, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2012-6039Nov 26, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.

  • CVE-2012-6038Nov 26, 2012
    risk 0.03cvss epss 0.03

    admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2)…

  • CVE-2012-5520Nov 26, 2012
    risk 0.00cvss epss 0.03

    The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request.

  • CVE-2012-2438Nov 26, 2012
    risk 0.00cvss epss 0.02

    ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.

  • CVE-2012-2437Nov 26, 2012
    risk 0.03cvss epss 0.02

    cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

  • CVE-2012-0698Nov 26, 2012
    risk 0.04cvss epss 0.11

    tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.

  • CVE-2012-6037Nov 24, 2012
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in…

  • CVE-2012-5533Nov 24, 2012
    risk 0.04cvss epss 0.12

    The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.