VYPR

CVEs

345,868 total · page 6099 of 6,918

  • CVE-2010-1189Mar 31, 2010
    risk 0.00cvss epss 0.02

    MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation…

  • CVE-2010-1188Mar 31, 2010
    risk 0.00cvss epss 0.03

    Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN)…

  • CVE-2010-1187Mar 31, 2010
    risk 0.00cvss epss 0.00

    The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which…

  • CVE-2010-1030Mar 31, 2010
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.

  • CVE-2010-0450Mar 31, 2010
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote authenticated users to gain privileges via unknown vectors.

  • CVE-2010-0449Mar 31, 2010
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2010-0448Mar 31, 2010
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to obtain "unauthorized access to data" via unknown vectors.

  • CVE-2010-0132Mar 31, 2010
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input," a different…

  • CVE-2010-1219Mar 30, 2010
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-1218Mar 30, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-1217Mar 30, 2010
    risk 0.04cvss epss 0.06

    Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher…

  • CVE-2010-1216Mar 30, 2010
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. NOTE: some of these details are obtained from third…

  • CVE-2009-4763Mar 30, 2010
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the ClickHeat plugin, as used in phpMyVisites before 2.4, has unknown impact and attack vectors. NOTE: due to lack of details from the vendor, it is not clear whether this is related to CVE-2008-5793.

  • CVE-2010-0537Mar 30, 2010
    risk 0.00cvss epss 0.01

    DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.

  • CVE-2010-0535Mar 30, 2010
    risk 0.00cvss epss 0.01

    Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

  • CVE-2010-0534Mar 30, 2010
    risk 0.00cvss epss 0.01

    Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.

  • CVE-2010-0526Mar 30, 2010
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG encoding, which is not…

  • CVE-2010-0525Mar 30, 2010
    risk 0.00cvss epss 0.01

    Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force…

  • CVE-2010-0524Mar 30, 2010
    risk 0.00cvss epss 0.01

    The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request…

  • CVE-2010-0523Mar 30, 2010
    risk 0.00cvss epss 0.02

    Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.

  • CVE-2010-0522Mar 30, 2010
    risk 0.00cvss epss 0.02

    Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection via screen sharing.

  • CVE-2010-0521Mar 30, 2010
    risk 0.00cvss epss 0.02

    Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.

  • CVE-2010-0520Mar 30, 2010
    risk 0.04cvss epss 0.19

    Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length…

  • CVE-2010-0519Mar 30, 2010
    risk 0.04cvss epss 0.09

    Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.

  • CVE-2010-0518Mar 30, 2010
    risk 0.00cvss epss 0.03

    QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.

  • CVE-2010-0517Mar 30, 2010
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with M-JPEG encoding, which causes QuickTime to calculate a buffer size using…

  • CVE-2010-0516Mar 30, 2010
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding, which triggers memory corruption when the length of decompressed…

  • CVE-2010-0515Mar 30, 2010
    risk 0.00cvss epss 0.03

    QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.

  • CVE-2010-0514Mar 30, 2010
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.261 encoding.

  • CVE-2010-0513Mar 30, 2010
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.

  • CVE-2010-0512Mar 30, 2010
    risk 0.00cvss epss 0.02

    The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering…

  • CVE-2010-0511Mar 30, 2010
    risk 0.00cvss epss 0.01

    Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritten, which allows attackers to access a workflow via unspecified vectors.

  • CVE-2010-0510Mar 30, 2010
    risk 0.00cvss epss 0.02

    Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.

  • CVE-2010-0509Mar 30, 2010
    risk 0.00cvss epss 0.00

    SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.

  • CVE-2010-0508Mar 30, 2010
    risk 0.00cvss epss 0.02

    Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.

  • CVE-2010-0507Mar 30, 2010
    risk 0.00cvss epss 0.03

    Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.

  • CVE-2010-0506Mar 30, 2010
    risk 0.00cvss epss 0.03

    Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.

  • CVE-2010-0505Mar 30, 2010
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImageReadGetBytesAtOffset…

  • CVE-2010-0504Mar 30, 2010
    risk 0.00cvss epss 0.03

    Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

  • CVE-2010-0503Mar 30, 2010
    risk 0.00cvss epss 0.02

    Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

  • CVE-2010-0502Mar 30, 2010
    risk 0.00cvss epss 0.01

    iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.

  • CVE-2010-0501Mar 30, 2010
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote authenticated users to read arbitrary files via crafted filenames.

  • CVE-2010-0500Mar 30, 2010
    risk 0.00cvss epss 0.02

    Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."

  • CVE-2010-0498Mar 30, 2010
    risk 0.00cvss epss 0.00

    Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.

  • CVE-2010-0497Mar 30, 2010
    risk 0.00cvss epss 0.03

    Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file type in an internet enabled disk image, which makes it easier for user-assisted remote attackers to execute arbitrary code via a package file type.

  • CVE-2010-0065Mar 30, 2010
    risk 0.00cvss epss 0.02

    Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.

  • CVE-2010-0064Mar 30, 2010
    risk 0.00cvss epss 0.00

    DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.

  • CVE-2010-0063Mar 30, 2010
    risk 0.00cvss epss 0.02

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content…

  • CVE-2010-0062Mar 30, 2010
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an…

  • CVE-2010-0060Mar 30, 2010
    risk 0.00cvss epss 0.03

    CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.