VYPR

CVEs

386,781 total · page 6670 of 7,736

  • CVE-2012-4515Nov 11, 2012
    risk 0.04cvss —epss 0.06

    Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

  • CVE-2012-4514Nov 11, 2012
    risk 0.04cvss —epss 0.10

    rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

  • CVE-2012-4513Nov 11, 2012
    risk 0.04cvss —epss 0.13

    khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

  • CVE-2012-4505Nov 11, 2012
    risk 0.00cvss —epss 0.03

    Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length size in an HTTP response header for a proxy.pac file request, a different vulnerability than…

  • CVE-2012-4504Nov 11, 2012
    risk 0.00cvss —epss 0.03

    Stack-based buffer overflow in the url::get_pac function in url.cpp in libproxy 0.4.x before 0.4.9 allows remote servers to have an unspecified impact via a large proxy.pac file.

  • CVE-2012-3523Nov 11, 2012
    risk 0.00cvss —epss 0.03

    The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext…

  • CVE-2012-2455Nov 10, 2012
    risk 0.00cvss —epss 0.01

    Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.

  • CVE-2012-3758Nov 9, 2012
    risk 0.00cvss —epss 0.05

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.

  • CVE-2012-3757Nov 9, 2012
    risk 0.00cvss —epss 0.05

    Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.

  • CVE-2012-3756Nov 9, 2012
    risk 0.00cvss —epss 0.06

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rnet box in an MP4 movie file.

  • CVE-2012-3755Nov 9, 2012
    risk 0.04cvss —epss 0.10

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.

  • CVE-2012-3754Nov 9, 2012
    risk 0.00cvss —epss 0.04

    Use-after-free vulnerability in the Clear method in the ActiveX control in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

  • CVE-2012-3753Nov 9, 2012
    risk 0.06cvss —epss 0.35

    Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.

  • CVE-2012-3752Nov 9, 2012
    risk 0.06cvss —epss 0.36

    Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file.

  • CVE-2012-3751Nov 9, 2012
    risk 0.00cvss —epss 0.04

    Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with a crafted _qtactivex_ parameter in an OBJECT element.

  • CVE-2011-1374Nov 9, 2012
    risk 0.00cvss —epss 0.05

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a PICT file.

  • CVE-2012-5171Nov 8, 2012
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Be Graph BeZIP before 3.10 allows remote attackers to create or overwrite arbitrary files via a crafted archive file.

  • CVE-2012-4023Nov 8, 2012
    risk 0.00cvss —epss 0.01

    CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • CVE-2012-4022Nov 8, 2012
    risk 0.00cvss —epss 0.02

    Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.

  • CVE-2012-4021Nov 8, 2012
    risk 0.00cvss —epss 0.01

    MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vectors.

  • CVE-2012-4020Nov 8, 2012
    risk 0.00cvss —epss 0.01

    MosP kintai kanri before 4.1.0 does not enforce privilege requirements, which allows remote authenticated users to read other users' information via unspecified vectors.

  • CVE-2012-3315Nov 8, 2012
    risk 0.00cvss —epss 0.03

    The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to…

  • CVE-2012-5424Nov 7, 2012
    risk 0.00cvss —epss 0.02

    Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sending a valid username…

  • CVE-2012-3270Nov 7, 2012
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3269.

  • CVE-2012-3269Nov 7, 2012
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270.

  • CVE-2012-5128Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-5127Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.

  • CVE-2012-5126Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.

  • CVE-2012-5125Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.

  • CVE-2012-5124Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-5123Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2012-5122Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • CVE-2012-5121Nov 7, 2012
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.

  • CVE-2012-5120Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.

  • CVE-2012-5119Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.

  • CVE-2012-5118Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2012-5117Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.

  • CVE-2012-5116Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.

  • CVE-2012-5115Nov 7, 2012
    risk 0.00cvss —epss 0.01

    Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger "wild writes."

  • CVE-2012-5280Nov 7, 2012
    risk 0.01cvss —epss 0.11

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600;…

  • CVE-2012-5279Nov 7, 2012
    risk 0.01cvss —epss 0.07

    Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK…

  • CVE-2012-5278Nov 7, 2012
    risk 0.01cvss —epss 0.09

    Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK…

  • CVE-2012-5277Nov 7, 2012
    risk 0.01cvss —epss 0.11

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600;…

  • CVE-2012-5276Nov 7, 2012
    risk 0.01cvss —epss 0.11

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600;…

  • CVE-2012-5275Nov 7, 2012
    risk 0.01cvss —epss 0.11

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600;…

  • CVE-2012-5274Nov 7, 2012
    risk 0.01cvss —epss 0.11

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600;…

  • CVE-2011-5243Nov 6, 2012
    risk 0.00cvss —epss 0.01

    TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2011-5242Nov 6, 2012
    risk 0.00cvss —epss 0.01

    tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2011-5241Nov 6, 2012
    risk 0.00cvss —epss 0.01

    Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2011-5240Nov 6, 2012
    risk 0.00cvss —epss 0.01

    Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.