VYPR

CVEs

346,392 total · page 5991 of 6,928

  • CVE-2008-7296Aug 9, 2011
    risk 0.00cvss epss 0.01

    Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security…

  • CVE-2008-7295Aug 9, 2011
    risk 0.00cvss epss 0.05

    Microsoft Internet Explorer cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict…

  • CVE-2008-7294Aug 9, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict…

  • CVE-2008-7293Aug 9, 2011
    risk 0.00cvss epss 0.02

    Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport…

  • CVE-2008-7292Aug 9, 2011
    risk 0.00cvss epss 0.00

    Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulnerability than…

  • CVE-2011-3009Aug 5, 2011
    risk 0.00cvss epss 0.02

    Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to…

  • CVE-2011-3008Aug 5, 2011
    risk 0.00cvss epss 0.02

    The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative…

  • CVE-2011-2900Aug 5, 2011
    risk 0.04cvss epss 0.13

    Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute…

  • CVE-2011-2721Aug 5, 2011
    risk 0.00cvss epss 0.03

    Off-by-one error in the cli_hm_scan function in matcher-hash.c in libclamav in ClamAV before 0.97.2 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message that is not properly handled during certain hash calculations.

  • CVE-2011-2720Aug 5, 2011
    risk 0.00cvss epss 0.03

    The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

  • CVE-2011-2705Aug 5, 2011
    risk 0.00cvss epss 0.02

    The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random…

  • CVE-2011-2686Aug 5, 2011
    risk 0.00cvss epss 0.03

    Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to…

  • CVE-2011-2591Aug 5, 2011
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to…

  • CVE-2011-1340Aug 5, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in skins/plone_templates/default_error_message.pt in Plone before 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the type_name parameter to Members/ipa/createObject.

  • CVE-2011-2764Aug 4, 2011
    risk 0.01cvss epss 0.09

    The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to…

  • CVE-2011-2701Aug 4, 2011
    risk 0.00cvss epss 0.02

    The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.

  • CVE-2011-1412Aug 4, 2011
    risk 0.00cvss epss 0.04

    sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.

  • CVE-2011-0252Aug 4, 2011
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STTS atoms in a QuickTime movie file.

  • CVE-2011-0251Aug 4, 2011
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSZ atoms in a QuickTime movie file.

  • CVE-2011-0250Aug 4, 2011
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSS atoms in a QuickTime movie file.

  • CVE-2011-0249Aug 4, 2011
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSC atoms in a QuickTime movie file.

  • CVE-2011-0248Aug 4, 2011
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL file.

  • CVE-2011-0247Aug 4, 2011
    risk 0.00cvss epss 0.05

    Multiple stack-based buffer overflows in Apple QuickTime before 7.7 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie.

  • CVE-2011-0246Aug 4, 2011
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.

  • CVE-2011-0245Aug 4, 2011
    risk 0.00cvss epss 0.04

    Buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pict file.

  • CVE-2011-2819Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.

  • CVE-2011-2818Aug 3, 2011
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.

  • CVE-2011-2805Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.

  • CVE-2011-2804Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

  • CVE-2011-2803Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2802Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.

  • CVE-2011-2801Aug 3, 2011
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the frame loader.

  • CVE-2011-2800Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.

  • CVE-2011-2799Aug 3, 2011
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.

  • CVE-2011-2798Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allows remote attackers to have an unspecified impact via a crafted web site.

  • CVE-2011-2797Aug 3, 2011
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.

  • CVE-2011-2796Aug 3, 2011
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-2795Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."

  • CVE-2011-2794Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2793Aug 3, 2011
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media selectors.

  • CVE-2011-2792Aug 3, 2011
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.

  • CVE-2011-2791Aug 3, 2011
    risk 0.00cvss epss 0.01

    The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

  • CVE-2011-2790Aug 3, 2011
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.

  • CVE-2011-2789Aug 3, 2011
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to instantiation of the Pepper plug-in.

  • CVE-2011-2788Aug 3, 2011
    risk 0.00cvss epss 0.01

    Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.

  • CVE-2011-2787Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

  • CVE-2011-2786Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.

  • CVE-2011-2785Aug 3, 2011
    risk 0.00cvss epss 0.01

    The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.

  • CVE-2011-2784Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.

  • CVE-2011-2783Aug 3, 2011
    risk 0.00cvss epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.