VYPR

CVEs

386,743 total · page 6687 of 7,735

  • CVE-2012-2578Sep 19, 2012
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a SCRIPT element, (3) a…

  • CVE-2012-0272Sep 19, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.

  • CVE-2012-0271Sep 19, 2012
    risk 0.04cvss —epss 0.17

    Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as…

  • CVE-2011-3827Sep 19, 2012
    risk 0.00cvss —epss 0.04

    The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.

  • CVE-2012-3258Sep 19, 2012
    risk 0.01cvss —epss 0.10

    Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2012-1660Sep 18, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content…

  • CVE-2012-1659Sep 18, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-1658Sep 18, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Read More Link module 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users with the access administration pages permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-1657Sep 18, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class name.

  • CVE-2012-1656Sep 18, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

  • CVE-2012-1655Sep 18, 2012
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the UC PayDutchGroup / WeDeal payment module 6.x-1.0 for Drupal allows remote authenticated users to obtain account credentials via unknown attack vectors.

  • CVE-2012-1654Sep 18, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML via the title parameter…

  • CVE-2012-1901Sep 18, 2012
    risk 0.03cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of…

  • CVE-2012-1184Sep 18, 2012
    risk 0.04cvss —epss 0.16

    Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest…

  • CVE-2012-1183Sep 18, 2012
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option is used and the internal_timing option is off, allows remote…

  • CVE-2011-4941Sep 18, 2012
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors.

  • CVE-2012-4425Sep 18, 2012
    risk 0.03cvss —epss 0.01

    libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the…

  • CVE-2012-4413Sep 18, 2012
    risk 0.00cvss —epss 0.02

    OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

  • CVE-2012-4405Sep 18, 2012
    risk 0.01cvss —epss 0.07

    Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary…

  • CVE-2012-3547Sep 18, 2012
    risk 0.00cvss —epss 0.06

    Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client…

  • CVE-2012-3524Sep 18, 2012
    risk 0.03cvss —epss 0.04

    libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is…

  • CVE-2012-3034Sep 18, 2012
    risk 0.00cvss —epss 0.02

    WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.

  • CVE-2012-3032Sep 18, 2012
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.

  • CVE-2012-3031Sep 18, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP…

  • CVE-2012-3030Sep 18, 2012
    risk 0.00cvss —epss 0.03

    WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.

  • CVE-2012-3028Sep 18, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.

  • CVE-2012-4969HigKEVSep 18, 2012
    risk 0.74cvss 8.1epss 0.80

    Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

  • CVE-2012-2994Sep 18, 2012
    risk 0.04cvss —epss 0.06

    The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.

  • CVE-2012-2993MedSep 18, 2012
    risk 0.39cvss 5.9epss 0.04

    Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

  • CVE-2012-2062Sep 17, 2012
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2012-2061Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors involving "not checking tokens."

  • CVE-2012-2060Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-2059Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-2058Sep 17, 2012
    risk 0.00cvss —epss 0.01

    The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

  • CVE-2012-2057Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.

  • CVE-2012-2056Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Content Lock module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2012-1899Sep 17, 2012
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.

  • CVE-2012-4968Sep 17, 2012
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5)…

  • CVE-2011-4962Sep 17, 2012
    risk 0.00cvss —epss 0.04

    code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

  • CVE-2011-4961Sep 17, 2012
    risk 0.00cvss —epss 0.02

    SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

  • CVE-2011-4960Sep 17, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2011-4959Sep 17, 2012
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2010-5079Sep 17, 2012
    risk 0.00cvss —epss 0.02

    SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended…

  • CVE-2010-5078Sep 17, 2012
    risk 0.00cvss —epss 0.02

    SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2)…

  • CVE-2010-4824Sep 17, 2012
    risk 0.00cvss —epss 0.03

    SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.

  • CVE-2010-4823Sep 17, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitrary web script or HTML via…

  • CVE-2010-4822Sep 17, 2012
    risk 0.00cvss —epss 0.02

    core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.

  • CVE-2012-2996Sep 17, 2012
    risk 0.03cvss —epss 0.02

    Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin accounts via a saveAuth action.

  • CVE-2012-2995Sep 17, 2012
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter…

  • CVE-2012-2575Sep 17, 2012
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.