VYPR

CVEs

386,791 total · page 6668 of 7,736

  • CVE-2012-4959Nov 18, 2012
    risk 0.09cvss —epss 0.71

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

  • CVE-2012-4958Nov 18, 2012
    risk 0.09cvss —epss 0.74

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

  • CVE-2012-4957Nov 18, 2012
    risk 0.08cvss —epss 0.68

    Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.

  • CVE-2012-4956Nov 18, 2012
    risk 0.06cvss —epss 0.38

    Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

  • CVE-2012-4575Nov 18, 2012
    risk 0.00cvss —epss 0.02

    The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

  • CVE-2012-5917Nov 17, 2012
    risk 0.03cvss —epss 0.03

    SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file.

  • CVE-2012-5916Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.

  • CVE-2012-5915Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5)…

  • CVE-2012-5914Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are…

  • CVE-2012-5913Nov 17, 2012
    risk 0.04cvss —epss 0.09

    Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.

  • CVE-2012-5912Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

  • CVE-2012-5911Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

  • CVE-2012-5910Nov 17, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

  • CVE-2012-5909Nov 17, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.

  • CVE-2012-5908Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.

  • CVE-2012-5907Nov 17, 2012
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.

  • CVE-2012-5906Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about: page or (2) the last visited URL in the LastVisitWriteEn function in function.js.

  • CVE-2012-5905Nov 17, 2012
    risk 0.03cvss —epss 0.03

    Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.

  • CVE-2012-5904Nov 17, 2012
    risk 0.00cvss —epss 0.06

    Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

  • CVE-2012-5903Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.php.

  • CVE-2012-5902Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.

  • CVE-2012-5901Nov 17, 2012
    risk 0.00cvss —epss 0.01

    DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or reports via a direct request to the file in the (1) log, (2) images, or (3) report directory.

  • CVE-2012-5900Nov 17, 2012
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start…

  • CVE-2012-5899Nov 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.

  • CVE-2012-5898Nov 17, 2012
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account settings.

  • CVE-2012-5897Nov 17, 2012
    risk 0.03cvss —epss 0.04

    The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

  • CVE-2012-5896Nov 17, 2012
    risk 0.09cvss —epss 0.69

    The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers to execute arbitrary code via a memory address in the first argument, related to an "uninitialized…

  • CVE-2012-5895Nov 17, 2012
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors.

  • CVE-2012-5894Nov 17, 2012
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.

  • CVE-2012-5893Nov 17, 2012
    risk 0.00cvss —epss 0.03

    Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php;.gif extension, then accessing it via a direct request to the file in tmp/files/.

  • CVE-2012-5892Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.

  • CVE-2012-5891Nov 17, 2012
    risk 0.03cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user passwords via a change…

  • CVE-2012-5890Nov 17, 2012
    risk 0.00cvss —epss 0.01

    The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.

  • CVE-2012-5889Nov 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-5888Nov 17, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-5887Nov 17, 2012
    risk 0.01cvss —epss 0.12

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to…

  • CVE-2012-5886Nov 17, 2012
    risk 0.01cvss —epss 0.09

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via…

  • CVE-2012-5885Nov 17, 2012
    risk 0.01cvss —epss 0.09

    The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count)…

  • CVE-2012-5856Nov 17, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-5172Nov 16, 2012
    risk 0.00cvss —epss 0.01

    The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application.

  • CVE-2012-2733Nov 16, 2012
    risk 0.01cvss —epss 0.09

    java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a…

  • CVE-2012-5884Nov 16, 2012
    risk 0.00cvss —epss 0.01

    The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.

  • CVE-2012-5883Nov 16, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or…

  • CVE-2012-5882Nov 16, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.

  • CVE-2012-5881Nov 16, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

  • CVE-2012-4199Nov 16, 2012
    risk 0.00cvss —epss 0.01

    template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names or private component names in certain…

  • CVE-2012-4198Nov 16, 2012
    risk 0.00cvss —epss 0.01

    The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users…

  • CVE-2012-4197Nov 16, 2012
    risk 0.00cvss —epss 0.02

    Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from private bugs via an obsolete=1 insert action.

  • CVE-2012-4189Nov 16, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as…

  • CVE-2012-5777Nov 16, 2012
    risk 0.00cvss —epss 0.02

    Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.