VYPR

CVEs

386,336 total · page 6791 of 7,727

  • CVE-2011-2800Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.

  • CVE-2011-2799Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.

  • CVE-2011-2798Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allows remote attackers to have an unspecified impact via a crafted web site.

  • CVE-2011-2797Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.

  • CVE-2011-2796Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2011-2795Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."

  • CVE-2011-2794Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

  • CVE-2011-2793Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media selectors.

  • CVE-2011-2792Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.

  • CVE-2011-2791Aug 3, 2011
    risk 0.00cvss —epss 0.01

    The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

  • CVE-2011-2790Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.

  • CVE-2011-2789Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to instantiation of the Pepper plug-in.

  • CVE-2011-2788Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.

  • CVE-2011-2787Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

  • CVE-2011-2786Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.

  • CVE-2011-2785Aug 3, 2011
    risk 0.00cvss —epss 0.01

    The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.

  • CVE-2011-2784Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.

  • CVE-2011-2783Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

  • CVE-2011-2782Aug 3, 2011
    risk 0.00cvss —epss 0.01

    The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.

  • CVE-2011-2711Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.

  • CVE-2011-2361Aug 3, 2011
    risk 0.00cvss —epss 0.01

    The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.

  • CVE-2011-2360Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.

  • CVE-2011-2359Aug 3, 2011
    risk 0.00cvss —epss 0.02

    Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

  • CVE-2011-2358Aug 3, 2011
    risk 0.00cvss —epss 0.01

    Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

  • CVE-2011-2975Aug 1, 2011
    risk 0.03cvss —epss 0.05

    Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.

  • CVE-2011-2719Aug 1, 2011
    risk 0.00cvss —epss 0.02

    libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and…

  • CVE-2011-2718Aug 1, 2011
    risk 0.00cvss —epss 0.02

    Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1)…

  • CVE-2011-2704Aug 1, 2011
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.

  • CVE-2011-2703Aug 1, 2011
    risk 0.00cvss —epss 0.03

    Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

  • CVE-2011-2643Aug 1, 2011
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

  • CVE-2011-2642Aug 1, 2011
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

  • CVE-2011-2403Aug 1, 2011
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2011-2402Aug 1, 2011
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-2399Aug 1, 2011
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in the Media Management Daemon (mmd) in HP Data Protector 6.11 and earlier allows remote attackers to cause a denial of service via unknown vectors.

  • CVE-2011-1744Aug 1, 2011
    risk 0.00cvss —epss 0.01

    EMC Captiva eInput 2.1.1 before 2.1.1.37 does not restrict the origin of calls to ActiveX functions, which allows remote attackers to read arbitrary files or cause a denial of service via a crafted web site.

  • CVE-2011-1743Aug 1, 2011
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in EMC Captiva eInput 2.1.1 before 2.1.1.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-1742Aug 1, 2011
    risk 0.00cvss —epss 0.00

    EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.

  • CVE-2011-2964Jul 29, 2011
    risk 0.00cvss —epss 0.05

    foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file, a different vulnerability than CVE-2011-2697.

  • CVE-2011-2697Jul 29, 2011
    risk 0.01cvss —epss 0.11

    foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.

  • CVE-2011-2694Jul 29, 2011
    risk 0.00cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd…

  • CVE-2011-2522Jul 29, 2011
    risk 0.04cvss —epss 0.10

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4)…

  • CVE-2011-2401Jul 29, 2011
    risk 0.00cvss —epss 0.04

    Session fixation vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to hijack web sessions via unspecified vectors.

  • CVE-2011-2400Jul 29, 2011
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in HP SiteScope 9.x, 10.x, and 11.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2011-2963Jul 29, 2011
    risk 0.04cvss —epss 0.08

    TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet…

  • CVE-2011-2962Jul 29, 2011
    risk 0.00cvss —epss 0.05

    Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via two unspecified ActiveX controls.

  • CVE-2011-2961Jul 29, 2011
    risk 0.01cvss —epss 0.06

    Heap-based buffer overflow in AngelServer.exe 6.0.11.3 in Sunway pNetPower allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UDP packet.

  • CVE-2011-2960Jul 29, 2011
    risk 0.04cvss —epss 0.18

    Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted URL.

  • CVE-2011-2959Jul 29, 2011
    risk 0.01cvss —epss 0.07

    Stack-based buffer overflow in the Open Database Connectivity (ODBC) service (Odbcixv9se.exe) in 7-Technologies Interactive Graphical SCADA System (IGSS) 9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted…

  • CVE-2011-2695Jul 28, 2011
    risk 0.00cvss —epss 0.00

    Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest…

  • CVE-2011-2689Jul 28, 2011
    risk 0.00cvss —epss 0.00

    The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups…