VYPR

CVEs

385,841 total · page 6867 of 7,717

  • CVE-2010-2371Jul 13, 2010
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1.1 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-2372.

  • CVE-2010-2370Jul 13, 2010
    risk 0.03cvss —epss 0.04

    Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.

  • CVE-2010-0916Jul 13, 2010
    risk 0.03cvss —epss 0.01

    Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rdist.

  • CVE-2010-0915Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Advanced Product Catalog component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

  • CVE-2010-0914Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail, Calendar, Address Book, and Instant Messaging.

  • CVE-2010-0913Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0912Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0911Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.

  • CVE-2010-0910Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Data Server component in Oracle TimesTen In-Memory Database 7.0.6.0 and 11.2.1.4.1 allows remote attackers to affect availability via unknown vectors.

  • CVE-2010-0909Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.

  • CVE-2010-0908Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2010-0907Jul 13, 2010
    risk 0.01cvss —epss 0.07

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0899, CVE-2010-0904, and CVE-2010-0906.

  • CVE-2010-0906Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2010-0905Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0904Jul 13, 2010
    risk 0.07cvss —epss 0.51

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0903Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.

  • CVE-2010-0902Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2010-0901Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Select Any Dictionary.

  • CVE-2010-0900Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.

  • CVE-2010-0899Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0907, and CVE-2010-0906.

  • CVE-2010-0898Jul 13, 2010
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2010-0892Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0873Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Data Server component in Oracle TimesTen In-Memory Database 7.0.6.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2010-0836Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0835Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Wireless component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0083Jul 13, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Oracle OpenSolaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

  • CVE-2009-3762Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-0081Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2381.

  • CVE-2009-3764Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the OpenSSO component in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2009-3763Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Access Manager / OpenSSO component in Oracle OpenSSO Enterprise 7.1, 7, 2005Q4, and 8.0 allows remote attackers to affect integrity via unknown vectors.

  • CVE-2010-2693Jul 13, 2010
    risk 0.03cvss —epss 0.01

    FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.

  • CVE-2010-2008Jul 13, 2010
    risk 0.04cvss —epss 0.09

    MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence,…

  • CVE-2010-2724Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the…

  • CVE-2010-2723Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2010-2722Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to inject arbitrary web script or HTML via the artist_id parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this…

  • CVE-2010-2721Jul 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary SQL commands via the artist_id parameter in an addalbum action.

  • CVE-2010-2720Jul 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in list.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-2719Jul 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in show.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-2718Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and unspecified vectors to (3)…

  • CVE-2010-2717Jul 13, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in manager/login.php in CruxSoftware CruxCMS 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the txtusername parameter.

  • CVE-2010-2716Jul 13, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.

  • CVE-2010-2715Jul 13, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

  • CVE-2010-2714Jul 13, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL commands via the album parameter.

  • CVE-2010-2523Jul 13, 2010
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.

  • CVE-2010-2522Jul 13, 2010
    risk 0.00cvss —epss 0.00

    The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.

  • CVE-2010-2227Jul 13, 2010
    risk 0.00cvss —epss 0.55

    Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that…

  • CVE-2010-2702Jul 12, 2010
    risk 0.00cvss —epss 0.05

    Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to…

  • CVE-2010-2701Jul 12, 2010
    risk 0.03cvss —epss 0.05

    Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.

  • CVE-2010-2700Jul 12, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2010-2699Jul 12, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.