VYPR

CVEs

346,462 total · page 5963 of 6,930

  • CVE-2011-3636Dec 8, 2011
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.

  • CVE-2011-3179Dec 8, 2011
    risk 0.00cvss epss 0.01

    The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.

  • CVE-2011-2653Dec 8, 2011
    risk 0.09cvss epss 0.72

    Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.

  • CVE-2011-4695Dec 7, 2011
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. …

  • CVE-2011-4694Dec 7, 2011
    risk 0.01cvss epss 0.08

    Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step…

  • CVE-2011-4693Dec 7, 2011
    risk 0.01cvss epss 0.07

    Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the first of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead…

  • CVE-2011-4692Dec 7, 2011
    risk 0.00cvss epss 0.01

    WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted…

  • CVE-2011-4691Dec 7, 2011
    risk 0.00cvss epss 0.01

    Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript…

  • CVE-2011-4690Dec 7, 2011
    risk 0.00cvss epss 0.01

    Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

  • CVE-2011-4689Dec 7, 2011
    risk 0.01cvss epss 0.09

    Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript…

  • CVE-2011-4688Dec 7, 2011
    risk 0.00cvss epss 0.02

    Mozilla Firefox 8.0.1 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

  • CVE-2011-4687Dec 7, 2011
    risk 0.00cvss epss 0.02

    Opera before 11.60 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified content on a web page, as demonstrated by a page under the cisco.com home page.

  • CVE-2011-4686Dec 7, 2011
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Web Workers implementation in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

  • CVE-2011-4685Dec 7, 2011
    risk 0.00cvss epss 0.02

    Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as demonstrated by forbes.com.

  • CVE-2011-4684Dec 7, 2011
    risk 0.03cvss epss 0.06

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

  • CVE-2011-4683Dec 7, 2011
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Opera before 11.60 has unknown impact and attack vectors, related to a "moderately severe issue."

  • CVE-2011-4682Dec 7, 2011
    risk 0.00cvss epss 0.02

    The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Policy via vectors related to variables on different web sites.

  • CVE-2011-4681Dec 7, 2011
    risk 0.00cvss epss 0.02

    Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same…

  • CVE-2011-4680Dec 7, 2011
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-4679Dec 7, 2011
    risk 0.00cvss epss 0.01

    vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.

  • CVE-2011-4263Dec 7, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-2462CriKEVDec 7, 2011
    risk 0.86cvss 9.8epss 0.87

    Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown…

  • CVE-2010-5074Dec 7, 2011
    risk 0.00cvss epss 0.01

    The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain…

  • CVE-2010-5073Dec 7, 2011
    risk 0.00cvss epss 0.01

    The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this…

  • CVE-2010-5072Dec 7, 2011
    risk 0.00cvss epss 0.01

    The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

  • CVE-2010-5071Dec 7, 2011
    risk 0.01cvss epss 0.13

    The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by…

  • CVE-2010-5070Dec 7, 2011
    risk 0.00cvss epss 0.02

    The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different…

  • CVE-2010-5069Dec 7, 2011
    risk 0.00cvss epss 0.01

    The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.

  • CVE-2010-5068Dec 7, 2011
    risk 0.00cvss epss 0.01

    The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.

  • CVE-2002-2437Dec 7, 2011
    risk 0.00cvss epss 0.01

    The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive…

  • CVE-2002-2436Dec 7, 2011
    risk 0.00cvss epss 0.01

    The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted…

  • CVE-2002-2435Dec 7, 2011
    risk 0.01cvss epss 0.14

    The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue…

  • CVE-2011-4678Dec 6, 2011
    risk 0.00cvss epss 0.01

    The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests.

  • CVE-2011-4677Dec 6, 2011
    risk 0.00cvss epss 0.01

    One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

  • CVE-2011-4555Dec 6, 2011
    risk 0.00cvss epss 0.01

    One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address.

  • CVE-2011-4554Dec 6, 2011
    risk 0.00cvss epss 0.01

    One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue.

  • CVE-2011-4553Dec 6, 2011
    risk 0.00cvss epss 0.01

    Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites…

  • CVE-2011-4552Dec 6, 2011
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the description field of (1) a new vote or (2) the eject member proposal feature.

  • CVE-2011-4130Dec 6, 2011
    risk 0.01cvss epss 0.13

    Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.

  • CVE-2011-4675Dec 5, 2011
    risk 0.00cvss epss 0.03

    The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these characters in strings received from the network, which might allow remote…

  • CVE-2011-4543Dec 5, 2011
    risk 0.00cvss epss 0.03

    Multiple directory traversal vulnerabilities in osCommerce 3.0.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) set or (2) module parameter to (a) OM/Core/Site/Admin/Application/templates_modules/pages/info.php, (b)…

  • CVE-2011-4356Dec 5, 2011
    risk 0.00cvss epss 0.00

    Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, celeryd-multi, and celeryev, which allows local users to gain privileges via…

  • CVE-2011-4162Dec 5, 2011
    risk 0.04cvss epss 0.08

    The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap…

  • CVE-2011-4052Dec 5, 2011
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name.

  • CVE-2011-4051Dec 5, 2011
    risk 0.09cvss epss 0.69

    CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

  • CVE-2011-2397Dec 5, 2011
    risk 0.00cvss epss 0.05

    The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted opcode 13 request that triggers use of the LaunchCompoundFileAnalyzer class to send request data to the System.getRunTime.exec method.

  • CVE-2011-1932Dec 5, 2011
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers to overwrite arbitrary files via . (dot) characters in a pathname that is used for a file transfer in an Internet game.

  • CVE-2011-4674Dec 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.

  • CVE-2011-4673Dec 2, 2011
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2011-4672Dec 2, 2011
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _partner_list.php, (2) proioncategory_list.php, (3) _rantevou_list.php, (4)…