VYPR

CVEs

386,394 total · page 6784 of 7,728

  • CVE-2011-2858Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2857Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.

  • CVE-2011-2856Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

  • CVE-2011-2855Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

  • CVE-2011-2854Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."

  • CVE-2011-2853Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.

  • CVE-2011-2852Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Off-by-one error in Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-2851Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly handle video, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2850Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2849Sep 19, 2011
    risk 0.00cvss —epss 0.01

    The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

  • CVE-2011-2848Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

  • CVE-2011-2847Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

  • CVE-2011-2846Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.

  • CVE-2011-2844Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2843Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2842Sep 19, 2011
    risk 0.00cvss —epss 0.01

    The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.

  • CVE-2011-2841Sep 19, 2011
    risk 0.03cvss —epss 0.04

    Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

  • CVE-2011-2840Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."

  • CVE-2011-2838Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote attack vectors.

  • CVE-2011-2837Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

  • CVE-2011-2836Sep 19, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 14.0.835.163 does not require Infobar interaction before use of the Windows Media Player plug-in, which makes it easier for remote attackers to have an unspecified impact via crafted Flash content.

  • CVE-2011-2835Sep 19, 2011
    risk 0.00cvss —epss 0.00

    Race condition in Google Chrome before 14.0.835.163 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the certificate cache.

  • CVE-2011-2834Sep 19, 2011
    risk 0.00cvss —epss 0.02

    Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

  • CVE-2011-2738Sep 19, 2011
    risk 0.01cvss —epss 0.11

    Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix…

  • CVE-2011-1740Sep 19, 2011
    risk 0.00cvss —epss 0.01

    EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.

  • CVE-2011-3503Sep 16, 2011
    risk 0.00cvss —epss 0.04

    Untrusted search path vulnerability in eSignal 10.6.2425.1208, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse JRS_UT.dll that is located in the same folder as a .quo…

  • CVE-2011-3502Sep 16, 2011
    risk 0.03cvss —epss 0.06

    The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).

  • CVE-2011-3501Sep 16, 2011
    risk 0.03cvss —epss 0.03

    Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-Length value.

  • CVE-2011-3500Sep 16, 2011
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in the web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.

  • CVE-2011-3499Sep 16, 2011
    risk 0.04cvss —epss 0.15

    Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an EIDP packet with a large size field, which writes a zero byte to an arbitrary memory location.

  • CVE-2011-3498Sep 16, 2011
    risk 0.04cvss —epss 0.10

    Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.

  • CVE-2011-3497Sep 16, 2011
    risk 0.08cvss —epss 0.57

    service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

  • CVE-2011-3496Sep 16, 2011
    risk 0.04cvss —epss 0.14

    service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.

  • CVE-2011-3495Sep 16, 2011
    risk 0.04cvss —epss 0.10

    Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command.

  • CVE-2011-3494Sep 16, 2011
    risk 0.07cvss —epss 0.56

    WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName…

  • CVE-2011-3493Sep 16, 2011
    risk 0.04cvss —epss 0.08

    Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) domain, (2) report_domain, (3) register_datahub, or (4)…

  • CVE-2011-3492Sep 16, 2011
    risk 0.09cvss —epss 0.71

    Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034.

  • CVE-2011-3491Sep 16, 2011
    risk 0.04cvss —epss 0.16

    Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative Content-Length field.

  • CVE-2011-3490Sep 16, 2011
    risk 0.06cvss —epss 0.36

    Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.

  • CVE-2011-3489Sep 16, 2011
    risk 0.04cvss —epss 0.09

    RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related…

  • CVE-2011-3488Sep 16, 2011
    risk 0.03cvss —epss 0.04

    Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mws chart, (3) mwt template, or (4) mwl layout.

  • CVE-2011-3487Sep 16, 2011
    risk 0.04cvss —epss 0.07

    Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

  • CVE-2011-3486Sep 16, 2011
    risk 0.07cvss —epss 0.50

    Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.

  • CVE-2011-3321Sep 16, 2011
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a…

  • CVE-2011-3211Sep 16, 2011
    risk 0.00cvss —epss 0.05

    The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.

  • CVE-2011-3322Sep 15, 2011
    risk 0.08cvss —epss 0.65

    Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an…

  • CVE-2011-2671Sep 15, 2011
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Megalith 12th edition through 27th edition allows remote attackers to gain administrative privileges via unknown vectors.

  • CVE-2011-3394Sep 15, 2011
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2011-3393Sep 15, 2011
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter.

  • CVE-2011-2442Sep 15, 2011
    risk 0.00cvss —epss 0.05

    Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error vulnerability."