VYPR

CVEs

346,483 total · page 5952 of 6,930

  • CVE-2011-3829Jan 29, 2012
    risk 0.04cvss epss 0.18

    ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.

  • CVE-2012-0053Jan 28, 2012
    risk 0.10cvss epss 0.83

    protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2)…

  • CVE-2012-0021Jan 28, 2012
    risk 0.02cvss epss 0.31

    The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a…

  • CVE-2012-0931CriJan 28, 2012
    risk 0.64cvss 9.8epss 0.05

    Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

  • CVE-2012-0930MedJan 28, 2012
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-0929HigJan 28, 2012
    risk 0.49cvss 7.5epss 0.05

    Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server.

  • CVE-2012-0814MedJan 27, 2012
    risk 0.43cvss 6.5epss 0.04

    The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by…

  • CVE-2012-0056Jan 27, 2012
    risk 0.04cvss epss 0.11

    The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc//mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

  • CVE-2012-0029Jan 27, 2012
    risk 0.00cvss epss 0.01

    Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.

  • CVE-2011-4622Jan 27, 2012
    risk 0.00cvss epss 0.00

    The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to…

  • CVE-2011-4608Jan 27, 2012
    risk 0.00cvss epss 0.03

    mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials…

  • CVE-2011-4330Jan 27, 2012
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.

  • CVE-2011-4325Jan 27, 2012
    risk 0.00cvss epss 0.00

    The NFS implementation in Linux kernel before 2.6.31-rc6 calls certain functions without properly initializing certain data, which allows local users to cause a denial of service (NULL pointer dereference and O_DIRECT oops), as demonstrated using diotest4 from LTP.

  • CVE-2011-4314Jan 27, 2012
    risk 0.00cvss epss 0.03

    message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote…

  • CVE-2011-4132Jan 27, 2012
    risk 0.00cvss epss 0.00

    The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."

  • CVE-2011-4110Jan 27, 2012
    risk 0.00cvss epss 0.00

    The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

  • CVE-2011-4077Jan 27, 2012
    risk 0.00cvss epss 0.01

    Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing…

  • CVE-2011-3874Jan 27, 2012
    risk 0.01cvss epss 0.12

    Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as…

  • CVE-2011-3626Jan 27, 2012
    risk 0.00cvss epss 0.02

    Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.

  • CVE-2011-2203Jan 27, 2012
    risk 0.00cvss epss 0.00

    The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record.

  • CVE-2011-1162Jan 27, 2012
    risk 0.00cvss epss 0.00

    The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.

  • CVE-2012-0807Jan 27, 2012
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute…

  • CVE-2012-0806Jan 27, 2012
    risk 0.00cvss epss 0.03

    Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.

  • CVE-2012-0395Jan 27, 2012
    risk 0.00cvss epss 0.03

    Buffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

  • CVE-2011-4354Jan 27, 2012
    risk 0.00cvss epss 0.04

    crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic…

  • CVE-2011-4143Jan 27, 2012
    risk 0.00cvss epss 0.01

    EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web system via unspecified vectors.

  • CVE-2012-0312Jan 26, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-0311Jan 26, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-1941Jan 26, 2012
    risk 0.00cvss epss 0.02

    Open redirect vulnerability in the redirector feature in phpMyAdmin 3.4.x before 3.4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2011-1940Jan 26, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1)…

  • CVE-2011-4276Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.

  • CVE-2012-0885Jan 25, 2012
    risk 0.00cvss epss 0.03

    chan_sip.c in Asterisk Open Source 1.8.x before 1.8.8.2 and 10.x before 10.0.1, when the res_srtp module is used and media support is improperly configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SDP message…

  • CVE-2011-3479Jan 25, 2012
    risk 0.03cvss epss 0.01

    Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable permissions for product-installation files, which allows local users to gain privileges by modifying a file.

  • CVE-2011-3478Jan 25, 2012
    risk 0.06cvss epss 0.39

    The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a…

  • CVE-2011-4867Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application.

  • CVE-2011-4866Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext password via a crafted application.

  • CVE-2011-4865Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.

  • CVE-2011-4864Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application.

  • CVE-2011-4863Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via a crafted application.

  • CVE-2011-4773Jan 25, 2012
    risk 0.00cvss epss 0.01

    The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

  • CVE-2011-4772Jan 25, 2012
    risk 0.00cvss epss 0.01

    The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

  • CVE-2011-4771Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or modify scanned files and a Google account via a crafted application.

  • CVE-2011-4770Jan 25, 2012
    risk 0.00cvss epss 0.01

    The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financial information via a crafted application.

  • CVE-2011-4769Jan 25, 2012
    risk 0.00cvss epss 0.01

    The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

  • CVE-2011-4705Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack."

  • CVE-2011-4704Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted application.

  • CVE-2011-4703Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modify call logs and a contact list via a crafted application.

  • CVE-2011-4702Jan 25, 2012
    risk 0.00cvss epss 0.01

    The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a contact list via a crafted application.

  • CVE-2011-4701Jan 25, 2012
    risk 0.00cvss epss 0.01

    The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted application.

  • CVE-2011-4700Jan 25, 2012
    risk 0.00cvss epss 0.01

    The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.