| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-1918 | 0.01 | — | 0.06 | Nov 2, 2011 | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message… | |||
| CVE-2010-5003 | 0.03 | — | 0.02 | Nov 1, 2011 | SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party… | |||
| CVE-2010-5002 | 0.03 | — | 0.02 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter. | |||
| CVE-2010-5001 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-4999 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter. | |||
| CVE-2010-4996 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |||
| CVE-2010-4995 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506. | |||
| CVE-2010-4994 | 0.00 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html. | |||
| CVE-2010-4993 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php. | |||
| CVE-2010-4992 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html. | |||
| CVE-2010-4991 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php. | |||
| CVE-2010-4990 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php. | |||
| CVE-2010-4989 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter. | |||
| CVE-2010-4988 | 0.03 | — | 0.02 | Nov 1, 2011 | PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers to execute arbitrary PHP code via a URL in the TMPL[path] parameter. | |||
| CVE-2010-4987 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter. | |||
| CVE-2010-4986 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter. | |||
| CVE-2010-4985 | 0.03 | — | 0.02 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box. | |||
| CVE-2010-4984 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box. | |||
| CVE-2010-4983 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-4982 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter. | |||
| CVE-2010-4981 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information. | |||
| CVE-2010-4980 | 0.03 | — | 0.02 | Nov 1, 2011 | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |||
| CVE-2010-4979 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter. | |||
| CVE-2010-4978 | 0.03 | — | 0.01 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter. | |||
| CVE-2010-4977 | 0.04 | — | 0.15 | Nov 1, 2011 | SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php. | |||
| CVE-2010-4976 | 0.03 | — | 0.02 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information. | |||
| CVE-2010-4975 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to index.php. | |||
| CVE-2010-4974 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-4973 | 0.00 | — | 0.01 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |||
| CVE-2010-4972 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter. | |||
| CVE-2010-4970 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-4969 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-4968 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php. | |||
| CVE-2011-4223 | 0.00 | — | 0.03 | Nov 1, 2011 | Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4222 | 0.04 | — | 0.07 | Nov 1, 2011 | Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document. | |||
| CVE-2011-4221 | 0.04 | — | 0.07 | Nov 1, 2011 | Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document. | |||
| CVE-2011-4220 | 0.04 | — | 0.07 | Nov 1, 2011 | Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4219 | 0.00 | — | 0.03 | Nov 1, 2011 | Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4218 | 0.00 | — | 0.03 | Nov 1, 2011 | Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4217 | 0.00 | — | 0.03 | Nov 1, 2011 | Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4216 | 0.00 | — | 0.03 | Nov 1, 2011 | Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |||
| CVE-2011-4215 | 0.00 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable. | |||
| CVE-2011-4214 | 0.00 | — | 0.03 | Nov 1, 2011 | OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie. | |||
| CVE-2011-4064 | 0.00 | — | 0.02 | Nov 1, 2011 | Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value. | |||
| CVE-2011-1915 | 0.00 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2011-0941 | 0.00 | — | 0.01 | Nov 1, 2011 | Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or… | |||
| CVE-2011-4213 | 0.00 | — | 0.00 | Oct 30, 2011 | The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restrictions and execute arbitrary commands via a file_blob_storage.os reference within the code parameter… | |||
| CVE-2011-4212 | 0.00 | — | 0.00 | Oct 30, 2011 | The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a dev_appserver.RestrictedPathFunction._original_os reference… | |||
| CVE-2011-4211 | 0.00 | — | 0.00 | Oct 30, 2011 | The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to bypass intended access restrictions and create arbitrary files via ALLOWED_MODES and ALLOWED_DIRS… | |||
| CVE-2011-1364 | 0.00 | — | 0.01 | Oct 30, 2011 | Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for… |
- CVE-2011-1918Nov 2, 2011risk 0.01cvss —epss 0.06
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message…
- CVE-2010-5003Nov 1, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party…
- CVE-2010-5002Nov 1, 2011risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter.
- CVE-2010-5001Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-4999Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter.
- CVE-2010-4996Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
- CVE-2010-4995Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.
- CVE-2010-4994Nov 1, 2011risk 0.00cvss —epss 0.01
SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs.html.
- CVE-2010-4993Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the eventcal (com_eventcal) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
- CVE-2010-4992Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the Payments Plus component 2.1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the type parameter to add.html.
- CVE-2010-4991Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.
- CVE-2010-4990Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php.
- CVE-2010-4989Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter.
- CVE-2010-4988Nov 1, 2011risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers to execute arbitrary PHP code via a URL in the TMPL[path] parameter.
- CVE-2010-4987Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
- CVE-2010-4986Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
- CVE-2010-4985Nov 1, 2011risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.
- CVE-2010-4984Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.
- CVE-2010-4983Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-4982Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.
- CVE-2010-4981Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
- CVE-2010-4980Nov 1, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
- CVE-2010-4979Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
- CVE-2010-4978Nov 1, 2011risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
- CVE-2010-4977Nov 1, 2011risk 0.04cvss —epss 0.15
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php.
- CVE-2010-4976Nov 1, 2011risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.
- CVE-2010-4975Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads description field in a showad action to index.php.
- CVE-2010-4974Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-4973Nov 1, 2011risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…
- CVE-2010-4972Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.
- CVE-2010-4970Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-4969Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-4968Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
- CVE-2011-4223Nov 1, 2011risk 0.00cvss —epss 0.03
Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4222Nov 1, 2011risk 0.04cvss —epss 0.07
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
- CVE-2011-4221Nov 1, 2011risk 0.04cvss —epss 0.07
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
- CVE-2011-4220Nov 1, 2011risk 0.04cvss —epss 0.07
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4219Nov 1, 2011risk 0.00cvss —epss 0.03
Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4218Nov 1, 2011risk 0.00cvss —epss 0.03
Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4217Nov 1, 2011risk 0.00cvss —epss 0.03
Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4216Nov 1, 2011risk 0.00cvss —epss 0.03
Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
- CVE-2011-4215Nov 1, 2011risk 0.00cvss —epss 0.01
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
- CVE-2011-4214Nov 1, 2011risk 0.00cvss —epss 0.03
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.
- CVE-2011-4064Nov 1, 2011risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.
- CVE-2011-1915Nov 1, 2011risk 0.00cvss —epss 0.01
SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2011-0941Nov 1, 2011risk 0.00cvss —epss 0.01
Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or…
- CVE-2011-4213Oct 30, 2011risk 0.00cvss —epss 0.00
The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restrictions and execute arbitrary commands via a file_blob_storage.os reference within the code parameter…
- CVE-2011-4212Oct 30, 2011risk 0.00cvss —epss 0.00
The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a dev_appserver.RestrictedPathFunction._original_os reference…
- CVE-2011-4211Oct 30, 2011risk 0.00cvss —epss 0.00
The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to bypass intended access restrictions and create arbitrary files via ALLOWED_MODES and ALLOWED_DIRS…
- CVE-2011-1364Oct 30, 2011risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for…