VYPR

CVEs

386,781 total · page 6674 of 7,736

  • CVE-2012-4173Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.

  • CVE-2012-4172Oct 23, 2012
    risk 0.01cvss —epss 0.10

    Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2012-4174, CVE-2012-4175, and CVE-2012-5273.

  • CVE-2012-5455Oct 22, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "typographical error."

  • CVE-2012-5454Oct 22, 2012
    risk 0.00cvss —epss 0.02

    user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

  • CVE-2012-5453Oct 22, 2012
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-5167.

  • CVE-2012-5452Oct 22, 2012
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en]…

  • CVE-2012-5169Oct 22, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML via the (1) pathext, (2) popup, (3) framed, or (4) file parameter.

  • CVE-2012-5168Oct 22, 2012
    risk 0.00cvss —epss 0.03

    ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_inline_editor_submit.php.

  • CVE-2012-5167Oct 22, 2012
    risk 0.03cvss —epss 0.05

    Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/index_inline_editor_submit.php or (2) user/index_inline_editor_submit.php; or (3) id parameter to…

  • CVE-2012-4990Oct 22, 2012
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitrary SQL commands via the ids[] parameter in a link action.

  • CVE-2012-4989Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.

  • CVE-2012-4773Oct 22, 2012
    risk 0.03cvss —epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an…

  • CVE-2012-4772Oct 22, 2012
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter.

  • CVE-2012-4771Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/accounts/, (2) admin/manage/, or (3) admin/manage/blocks/edit/; or (4) group parameter to…

  • CVE-2012-4518Oct 22, 2012
    risk 0.00cvss —epss 0.00

    ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.

  • CVE-2012-4517Oct 22, 2012
    risk 0.00cvss —epss 0.03

    ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.

  • CVE-2012-4516Oct 22, 2012
    risk 0.00cvss —epss 0.02

    librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

  • CVE-2012-4511Oct 22, 2012
    risk 0.00cvss —epss 0.02

    services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

  • CVE-2012-4507Oct 22, 2012
    risk 0.00cvss —epss 0.03

    The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.

  • CVE-2012-4506Oct 22, 2012
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.

  • CVE-2012-4436Oct 22, 2012
    risk 0.00cvss —epss 0.01

    Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.

  • CVE-2012-4435Oct 22, 2012
    risk 0.00cvss —epss 0.02

    fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.

  • CVE-2012-4406CriOct 22, 2012
    risk 0.57cvss 9.8epss 0.07

    OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

  • CVE-2012-4232Oct 22, 2012
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to execute arbitrary SQL commands via the memberloginid cookie.

  • CVE-2012-4231Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

  • CVE-2012-3466Oct 22, 2012
    risk 0.00cvss —epss 0.00

    GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.

  • CVE-2012-2679Oct 22, 2012
    risk 0.00cvss —epss 0.00

    Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-readable) for /var/log/rhncfg-actions, which allows local users to obtain sensitive information about the rhncfg-client actions by reading the file.

  • CVE-2012-1900Oct 22, 2012
    risk 0.03cvss —epss 0.03

    Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

  • CVE-2012-1154Oct 22, 2012
    risk 0.00cvss —epss 0.03

    mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to…

  • CVE-2011-5212Oct 22, 2012
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.

  • CVE-2011-5211Oct 22, 2012
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.

  • CVE-2011-4129Oct 22, 2012
    risk 0.00cvss —epss 0.02

    (1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle…

  • CVE-2010-4821Oct 22, 2012
    risk 0.00cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

  • CVE-2012-4751Oct 22, 2012
    risk 0.03cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a…

  • CVE-2012-3001Oct 22, 2012
    risk 0.05cvss —epss 0.27

    Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."

  • CVE-2012-4933Oct 20, 2012
    risk 0.07cvss —epss 0.44

    The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain…

  • CVE-2012-2167Oct 20, 2012
    risk 0.00cvss —epss 0.03

    The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.

  • CVE-2012-4845Oct 20, 2012
    risk 0.00cvss —epss 0.02

    The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

  • CVE-2012-4826Oct 20, 2012
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.

  • CVE-2012-2972Oct 20, 2012
    risk 0.00cvss —epss 0.03

    The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remote attackers to cause a denial of service (service crash) via a crafted request.

  • CVE-2012-2971Oct 20, 2012
    risk 0.00cvss —epss 0.04

    The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted request.

  • CVE-2012-2290Oct 18, 2012
    risk 0.00cvss —epss 0.04

    The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.

  • CVE-2012-2284Oct 18, 2012
    risk 0.00cvss —epss 0.00

    The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.

  • CVE-2012-0306Oct 18, 2012
    risk 0.00cvss —epss 0.03

    Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted backup file.

  • CVE-2012-5095Oct 17, 2012
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.

  • CVE-2012-5094Oct 17, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors related to User Group Management.

  • CVE-2012-5093Oct 17, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unknown vectors related to Global Spec Management.

  • CVE-2012-5092Oct 17, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Supply Chain Relationship Management.

  • CVE-2012-5091Oct 17, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Agile Product Supplier Collaboration for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors related to Supplier Portal.

  • CVE-2012-5090Oct 17, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Document Reference Library.