VYPR

CVEs

345,868 total · page 6102 of 6,918

  • CVE-2010-1108Mar 25, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-1107Mar 25, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface."

  • CVE-2010-1106Mar 25, 2010
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

  • CVE-2010-1105Mar 25, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in cgi/index.php in AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter.

  • CVE-2010-1104Mar 25, 2010
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.

  • CVE-2010-1103Mar 24, 2010
    risk 0.00cvss epss 0.01

    Integer overflow in Stainless allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

  • CVE-2010-1102Mar 24, 2010
    risk 0.00cvss epss 0.01

    Integer overflow in OmniWeb allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

  • CVE-2010-1101Mar 24, 2010
    risk 0.00cvss epss 0.01

    Integer overflow in Alexander Clauss iCab allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

  • CVE-2010-1100Mar 24, 2010
    risk 0.00cvss epss 0.01

    Integer overflow in Arora allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

  • CVE-2010-1099Mar 24, 2010
    risk 0.00cvss epss 0.01

    Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.

  • CVE-2010-0619Mar 24, 2010
    risk 0.03cvss epss 0.05

    Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser printers and multi-function printers allows remote attackers to execute arbitrary code or cause a denial of service (device hang)…

  • CVE-2010-0618Mar 24, 2010
    risk 0.00cvss epss 0.01

    The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows remote attackers to cause a denial of service (TCP outage) by making many passive…

  • CVE-2009-2907Mar 24, 2010
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source before 4.2.x, Hyperic HQ 4.0 Enterprise before 4.0.3.2, and Hyperic HQ 4.1 Enterprise before 4.1.2.1…

  • CVE-2010-1098Mar 24, 2010
    risk 0.01cvss epss 0.15

    The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.

  • CVE-2010-1097Mar 24, 2010
    risk 0.00cvss epss 0.01

    include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to…

  • CVE-2010-1096Mar 24, 2010
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in searchmatch.php in ScriptsFeed Dating Software allow remote attackers to execute arbitrary SQL commands via the (1) txtgender and (2) txtlookgender parameters. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2010-1095Mar 24, 2010
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown;…

  • CVE-2010-1094Mar 24, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in news.php in DZ EROTIK Auktionshaus V4rgo allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-1093Mar 24, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.

  • CVE-2010-1092Mar 24, 2010
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters.

  • CVE-2010-1091Mar 24, 2010
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.

  • CVE-2010-1090Mar 24, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the action parameter.

  • CVE-2010-1089Mar 24, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-0437Mar 24, 2010
    risk 0.04cvss epss 0.12

    The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer…

  • CVE-2010-1082Mar 23, 2010
    risk 0.00cvss epss 0.01

    Multiple directory traversal vulnerabilities in OI.Blogs 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via directory traversal sequences in the (1) theme parameter to loadStyles.php and the (2) scripts parameter to…

  • CVE-2010-1081Mar 23, 2010
    risk 0.04cvss epss 0.14

    Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2010-1080Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter.

  • CVE-2010-1079Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-1078Mar 23, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbitrary SQL commands via encoded null bytes ("%00") in the view parameter, which bypasses a protection mechanism.

  • CVE-2010-1077Mar 23, 2010
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

  • CVE-2010-1076Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is…

  • CVE-2010-1075Mar 23, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to execute arbitrary SQL commands via the subj parameter.

  • CVE-2010-1074Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging.

  • CVE-2010-1073Mar 23, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.

  • CVE-2010-1072Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in Sniggabo CMS 2.21 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2010-1071Mar 23, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in profil.php in phpMDJ 1.0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-1070Mar 23, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary SQL commands via the seid parameter in a forums viewcat action.

  • CVE-2010-1069Mar 23, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-1068Mar 23, 2010
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.

  • CVE-2010-1067Mar 23, 2010
    risk 0.03cvss epss 0.02

    E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb.

  • CVE-2010-1066Mar 23, 2010
    risk 0.03cvss epss 0.02

    AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.

  • CVE-2010-1065Mar 23, 2010
    risk 0.03cvss epss 0.02

    Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.

  • CVE-2010-1064Mar 23, 2010
    risk 0.03cvss epss 0.02

    Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb.

  • CVE-2010-1040Mar 23, 2010
    risk 0.00cvss epss 0.01

    The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.

  • CVE-2009-4736Mar 23, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in CommonSense CMS 5.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2010-1063Mar 23, 2010
    risk 0.00cvss epss 0.01

    Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1)…

  • CVE-2010-1062Mar 23, 2010
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of…

  • CVE-2010-1061Mar 23, 2010
    risk 0.00cvss epss 0.01

    Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) url/app/common.inc.php and (2)…

  • CVE-2010-1060Mar 23, 2010
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

  • CVE-2010-1059Mar 23, 2010
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter. NOTE: the…