VYPR

CVEs

345,868 total · page 6100 of 6,918

  • CVE-2010-0055Mar 30, 2010
    risk 0.00cvss epss 0.02

    xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.

  • CVE-2010-0533Mar 30, 2010
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.

  • CVE-2010-0059Mar 30, 2010
    risk 0.00cvss epss 0.05

    CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields,…

  • CVE-2010-0058Mar 30, 2010
    risk 0.00cvss epss 0.02

    freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.

  • CVE-2010-0057Mar 30, 2010
    risk 0.00cvss epss 0.01

    AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.

  • CVE-2010-0056Mar 30, 2010
    risk 0.00cvss epss 0.03

    Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.

  • CVE-2009-2801Mar 30, 2010
    risk 0.00cvss epss 0.02

    The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a "timing issue."

  • CVE-2010-1185Mar 29, 2010
    risk 0.04cvss epss 0.15

    Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a handshake packet to TCP port 7210. NOTE: some of these details are obtained from third party…

  • CVE-2010-1184Mar 29, 2010
    risk 0.01cvss epss 0.08

    The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.

  • CVE-2010-1183Mar 29, 2010
    risk 0.03cvss epss 0.00

    Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.

  • CVE-2010-0451Mar 29, 2010
    risk 0.00cvss epss 0.03

    The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests.

  • CVE-2010-1182Mar 29, 2010
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.

  • CVE-2009-4762Mar 29, 2010
    risk 0.00cvss epss 0.03

    MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than…

  • CVE-2010-1181Mar 29, 2010
    risk 0.00cvss epss 0.03

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a MARQUEE element.

  • CVE-2010-1180Mar 29, 2010
    risk 0.04cvss epss 0.08

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.

  • CVE-2010-1179Mar 29, 2010
    risk 0.04cvss epss 0.09

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to…

  • CVE-2010-1178Mar 29, 2010
    risk 0.00cvss epss 0.01

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.

  • CVE-2010-1177Mar 29, 2010
    risk 0.04cvss epss 0.07

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

  • CVE-2010-1176Mar 29, 2010
    risk 0.04cvss epss 0.09

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a…

  • CVE-2010-1175Mar 29, 2010
    risk 0.04cvss epss 0.14

    Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."

  • CVE-2010-1174Mar 29, 2010
    risk 0.03cvss epss 0.05

    Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information.

  • CVE-2010-0452Mar 29, 2010
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-4761Mar 29, 2010
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.

  • CVE-2009-4760Mar 29, 2010
    risk 0.03cvss epss 0.03

    Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.

  • CVE-2009-4759Mar 29, 2010
    risk 0.03cvss epss 0.05

    Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .BMX file.

  • CVE-2009-4758Mar 29, 2010
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .YUV file.

  • CVE-2009-4757Mar 29, 2010
    risk 0.03cvss epss 0.05

    Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: some of these details are obtained from third…

  • CVE-2009-4756Mar 29, 2010
    risk 0.04cvss epss 0.07

    Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

  • CVE-2009-4755Mar 29, 2010
    risk 0.04cvss epss 0.07

    Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.

  • CVE-2009-4754Mar 29, 2010
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

  • CVE-2009-4753Mar 29, 2010
    risk 0.03cvss epss 0.03

    Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service (TCP/IP outage) via long arguments to the (1) XRMD, (2) delete, (3) RNFR, or (4) RNTO command.

  • CVE-2010-1136Mar 27, 2010
    risk 0.00cvss epss 0.02

    The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

  • CVE-2010-1135Mar 27, 2010
    risk 0.00cvss epss 0.02

    The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.

  • CVE-2010-1134Mar 27, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.

  • CVE-2010-1133Mar 27, 2010
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.

  • CVE-2010-1132Mar 27, 2010
    risk 0.04cvss epss 0.09

    The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

  • CVE-2010-1131Mar 27, 2010
    risk 0.03cvss epss 0.04

    JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the substring.

  • CVE-2010-1130Mar 26, 2010
    risk 0.04cvss epss 0.09

    session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument…

  • CVE-2010-1129Mar 26, 2010
    risk 0.00cvss epss 0.03

    The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

  • CVE-2010-1128Mar 26, 2010
    risk 0.04cvss epss 0.08

    The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid…

  • CVE-2010-1127Mar 26, 2010
    risk 0.01cvss epss 0.18

    Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated…

  • CVE-2010-1126Mar 26, 2010
    risk 0.00cvss epss 0.02

    The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.

  • CVE-2010-1125Mar 26, 2010
    risk 0.00cvss epss 0.02

    The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls…

  • CVE-2009-4752Mar 26, 2010
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter.

  • CVE-2009-4751Mar 26, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

  • CVE-2009-4750Mar 26, 2010
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

  • CVE-2009-4749Mar 26, 2010
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x parameter to (1) message_box.php and (2) request.php.

  • CVE-2009-4748Mar 26, 2010
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

  • CVE-2009-4747Mar 26, 2010
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.

  • CVE-2009-4746Mar 26, 2010
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.