VYPR

CVEs

386,791 total · page 6659 of 7,736

  • CVE-2012-4792HigKEVDec 30, 2012
    risk 0.79cvss 8.8epss 0.79

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and…

  • CVE-2012-6369Dec 28, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting…

  • CVE-2012-5445Dec 28, 2012
    risk 0.00cvss —epss 0.00

    The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory…

  • CVE-2012-4932Dec 28, 2012
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the…

  • CVE-2012-4528Dec 28, 2012
    risk 0.04cvss —epss 0.13

    The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

  • CVE-2012-3873Dec 28, 2012
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5)…

  • CVE-2012-3872Dec 28, 2012
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.

  • CVE-2012-3871Dec 28, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

  • CVE-2012-3870Dec 28, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or (2) description parameter.

  • CVE-2012-0741Dec 28, 2012
    risk 0.00cvss —epss 0.01

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

  • CVE-2012-0738Dec 28, 2012
    risk 0.00cvss —epss 0.01

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

  • CVE-2012-6432Dec 27, 2012
    risk 0.00cvss —epss 0.01

    Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

  • CVE-2012-6431Dec 27, 2012
    risk 0.00cvss —epss 0.02

    Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

  • CVE-2012-5868Dec 27, 2012
    risk 0.00cvss —epss 0.02

    WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

  • CVE-2012-5532Dec 27, 2012
    risk 0.00cvss —epss 0.00

    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an…

  • CVE-2012-2669Dec 27, 2012
    risk 0.00cvss —epss 0.00

    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.

  • CVE-2012-6314Dec 26, 2012
    risk 0.00cvss —epss 0.02

    Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.

  • CVE-2012-5625Dec 26, 2012
    risk 0.00cvss —epss 0.02

    OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the…

  • CVE-2012-5483Dec 26, 2012
    risk 0.00cvss —epss 0.00

    tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and…

  • CVE-2012-5161Dec 26, 2012
    risk 0.00cvss —epss 0.06

    The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2012-0962Dec 26, 2012
    risk 0.00cvss —epss 0.02

    Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.

  • CVE-2012-0961Dec 26, 2012
    risk 0.00cvss —epss 0.00

    Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive…

  • CVE-2012-0958Dec 26, 2012
    risk 0.00cvss —epss 0.02

    content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

  • CVE-2012-6299Dec 26, 2012
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access restrictions via unknown vectors.

  • CVE-2012-6298Dec 26, 2012
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary commands or modify data via unknown vectors.

  • CVE-2012-4616Dec 26, 2012
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2012-5951Dec 26, 2012
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to the normal Unix System Services (USS) security level.

  • CVE-2012-4816Dec 26, 2012
    risk 0.00cvss —epss 0.01

    IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wizard) access restrictions by visiting context roots in HTTP sessions on port 8080.

  • CVE-2012-5591Dec 26, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.

  • CVE-2012-5590Dec 26, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2012-5589Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.

  • CVE-2012-5588Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via…

  • CVE-2012-5587Dec 26, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.

  • CVE-2012-5586Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."

  • CVE-2012-5585Dec 26, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel token.

  • CVE-2012-5584Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does not properly check node permissions, which allows remote attackers to read a node's headers by accessing a table of contents block.

  • CVE-2012-5183Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.

  • CVE-2012-5182Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted application.

  • CVE-2012-5180Dec 26, 2012
    risk 0.00cvss —epss 0.01

    The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

  • CVE-2012-5179Dec 26, 2012
    risk 0.00cvss —epss 0.00

    The Boat Browser application before 4.2 and Boat Browser Mini application before 3.9 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

  • CVE-2012-0432Dec 25, 2012
    risk 0.08cvss —epss 0.59

    Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.

  • CVE-2012-0430Dec 25, 2012
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.

  • CVE-2012-0429Dec 25, 2012
    risk 0.00cvss —epss 0.02

    dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.

  • CVE-2012-0428Dec 25, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-5932Dec 24, 2012
    risk 0.08cvss —epss 0.63

    Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.

  • CVE-2012-5931Dec 24, 2012
    risk 0.04cvss —epss 0.07

    Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.

  • CVE-2012-5930Dec 24, 2012
    risk 0.04cvss —epss 0.07

    The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted…

  • CVE-2012-4046Dec 24, 2012
    risk 0.00cvss —epss 0.01

    The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.

  • CVE-2012-0411Dec 24, 2012
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.

  • CVE-2012-6428Dec 23, 2012
    risk 0.00cvss —epss 0.02

    The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.