VYPR

CVEs

385,965 total · page 6833 of 7,720

  • CVE-2010-4582Dec 22, 2010
    risk 0.00cvss —epss 0.02

    Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.

  • CVE-2010-4581Dec 22, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."

  • CVE-2010-4580Dec 22, 2010
    risk 0.00cvss —epss 0.02

    Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site.

  • CVE-2010-4579Dec 22, 2010
    risk 0.00cvss —epss 0.02

    Opera before 11.00 does not properly constrain dialogs to appear on top of rendered documents, which makes it easier for remote attackers to trick users into interacting with a crafted web site that spoofs the (1) security information dialog or (2) download dialog.

  • CVE-2010-4333Dec 22, 2010
    risk 0.04cvss —epss 0.07

    Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.

  • CVE-2010-4332Dec 22, 2010
    risk 0.04cvss —epss 0.07

    Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.

  • CVE-2010-4275Dec 22, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) name or (2) descr parameter in an (a) update_usergroup or a (b) store_nas action to admin.php.

  • CVE-2010-2590Dec 22, 2010
    risk 0.07cvss —epss 0.47

    Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.

  • CVE-2010-1804Dec 22, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply.

  • CVE-2010-0039Dec 22, 2010
    risk 0.00cvss —epss 0.02

    The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary…

  • CVE-2009-2189Dec 22, 2010
    risk 0.00cvss —epss 0.01

    The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial…

  • CVE-2010-4578Dec 22, 2010
    risk 0.00cvss —epss 0.02

    Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

  • CVE-2010-4577HigDec 22, 2010
    risk 0.49cvss 7.5epss 0.02

    The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which…

  • CVE-2010-4576Dec 22, 2010
    risk 0.00cvss —epss 0.02

    browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via…

  • CVE-2010-4575Dec 22, 2010
    risk 0.00cvss —epss 0.01

    The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted…

  • CVE-2010-4574Dec 22, 2010
    risk 0.00cvss —epss 0.02

    The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a…

  • CVE-2010-4116Dec 22, 2010
    risk 0.01cvss —epss 0.12

    Unspecified vulnerability in HP StorageWorks Storage Mirroring 5.x before 5.2.2.1771.2 allows remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2010-1676Dec 22, 2010
    risk 0.01cvss —epss 0.08

    Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

  • CVE-2010-0114Dec 22, 2010
    risk 0.00cvss —epss 0.05

    fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a…

  • CVE-2010-4558Dec 17, 2010
    risk 0.00cvss —epss 0.01

    phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.

  • CVE-2010-4557Dec 17, 2010
    risk 0.04cvss —epss 0.12

    Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request…

  • CVE-2010-4556Dec 17, 2010
    risk 0.00cvss —epss 0.06

    Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods.

  • CVE-2010-4495Dec 17, 2010
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; ActiveMatrix BPM 1.0.1 and 1.0.2; Silver BPM Service 1.0.1; and…

  • CVE-2010-4481Dec 17, 2010
    risk 0.00cvss —epss 0.02

    phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, which calls the phpinfo function.

  • CVE-2010-4336Dec 17, 2010
    risk 0.00cvss —epss 0.02

    The cu_rrd_create_file function (src/utils_rrdcreate.c) in collectd 4.x before 4.9.4 and before 4.10.2 allow remote attackers to cause a denial of service (assertion failure) via a packet with a timestamp whose value is 10 or less, as demonstrated by creating RRD files using the…

  • CVE-2010-4262Dec 17, 2010
    risk 0.00cvss —epss 0.06

    Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.

  • CVE-2010-4115Dec 17, 2010
    risk 0.00cvss —epss 0.03

    HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges.

  • CVE-2010-3906Dec 17, 2010
    risk 0.03cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

  • CVE-2010-3616Dec 17, 2010
    risk 0.01cvss —epss 0.08

    ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP client service loss) by connecting to a port that is only intended for a failover peer, as…

  • CVE-2010-2603Dec 17, 2010
    risk 0.00cvss —epss 0.00

    RIM BlackBerry Desktop Software 4.7 through 6.0 for PC, and 1.0 for Mac, uses a weak password to encrypt a database backup file, which makes it easier for local users to decrypt the file via a brute force attack.

  • CVE-2010-2602Dec 17, 2010
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Enterprise Server 5.0.0 through 5.0.2, 4.1.6, and 4.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF…

  • CVE-2010-4553Dec 16, 2010
    risk 0.00cvss —epss 0.01

    An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

  • CVE-2010-4552Dec 16, 2010
    risk 0.00cvss —epss 0.02

    Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients.

  • CVE-2010-4551Dec 16, 2010
    risk 0.00cvss —epss 0.02

    IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation.

  • CVE-2010-4550Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.

  • CVE-2010-4549Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation.

  • CVE-2010-4548Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client.

  • CVE-2010-4547Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by…

  • CVE-2010-4546Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request.

  • CVE-2010-4545Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data.

  • CVE-2010-4544Dec 16, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-5036Dec 16, 2010
    risk 0.00cvss —epss 0.01

    traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation.

  • CVE-2009-5035Dec 16, 2010
    risk 0.00cvss —epss 0.01

    The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.

  • CVE-2009-5034Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating…

  • CVE-2009-5033Dec 16, 2010
    risk 0.00cvss —epss 0.01

    IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the…

  • CVE-2009-5032Dec 16, 2010
    risk 0.00cvss —epss 0.01

    The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

  • CVE-2010-3967Dec 16, 2010
    risk 0.05cvss —epss 0.20

    Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading…

  • CVE-2010-3966Dec 16, 2010
    risk 0.01cvss —epss 0.13

    Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS…

  • CVE-2010-3965Dec 16, 2010
    risk 0.01cvss —epss 0.12

    Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working…

  • CVE-2010-3964Dec 16, 2010
    risk 0.11cvss —epss 0.94

    Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP…