VYPR

CVEs

385,841 total · page 6869 of 7,717

  • CVE-2010-2663Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.60 allows remote attackers to cause a denial of service (application hang) via an ended event handler that changes the SRC attribute of an AUDIO element.

  • CVE-2010-2662Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.60 allows remote attackers to bypass the popup blocker via a javascript: URL and a "fake click."

  • CVE-2010-2661Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.54 on Windows and Mac OS X, and before 10.60 on UNIX platforms, does not properly restrict access to the full pathname of a file selected for upload, which allows remote attackers to obtain potentially sensitive information via unspecified DOM manipulations.

  • CVE-2010-2660Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.54 on Windows and Mac OS X, and before 10.60 on UNIX platforms, does not properly restrict certain uses of homograph characters in domain names, which makes it easier for remote attackers to spoof IDN domains via unspecified choices of characters.

  • CVE-2010-2659Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.50 on Windows, before 10.52 on Mac OS X, and before 10.60 on UNIX platforms makes widget properties accessible to third-party domains, which allows remote attackers to obtain potentially sensitive information via a crafted web site.

  • CVE-2010-2658Jul 8, 2010
    risk 0.00cvss —epss 0.02

    Opera before 10.60 does not properly restrict certain interaction between plug-ins, file inputs, and the clipboard, which allows user-assisted remote attackers to trigger the uploading of arbitrary files via a crafted web site.

  • CVE-2010-2657Jul 8, 2010
    risk 0.00cvss —epss 0.04

    Opera before 10.60 on Windows and Mac OS X does not properly prevent certain double-click operations from running a program located on a web site, which allows user-assisted remote attackers to execute arbitrary code via a crafted web page that bypasses a dialog.

  • CVE-2010-2656Jul 8, 2010
    risk 0.03cvss —epss 0.02

    The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core…

  • CVE-2010-2655Jul 8, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly…

  • CVE-2010-2654Jul 8, 2010
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2)…

  • CVE-2010-2445Jul 8, 2010
    risk 0.00cvss —epss 0.03

    freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require…

  • CVE-2010-2244Jul 8, 2010
    risk 0.00cvss —epss 0.02

    The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a…

  • CVE-2010-2631Jul 6, 2010
    risk 0.03cvss —epss 0.03

    LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability…

  • CVE-2010-2630Jul 6, 2010
    risk 0.03cvss —epss 0.05

    The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different…

  • CVE-2010-2652Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Google Chrome before 5.0.375.99 does not properly implement modal dialogs, which allows attackers to cause a denial of service (application crash) via unspecified vectors.

  • CVE-2010-2651Jul 6, 2010
    risk 0.00cvss —epss 0.01

    The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly perform style rendering, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

  • CVE-2010-2650Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Google Chrome before 5.0.375.99 has unknown impact and attack vectors, related to an "annoyance with print dialogs."

  • CVE-2010-2649Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (application crash) via an invalid image.

  • CVE-2010-2648Jul 6, 2010
    risk 0.00cvss —epss 0.02

    The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

  • CVE-2010-2647Jul 6, 2010
    risk 0.00cvss —epss 0.02

    Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.

  • CVE-2010-2646Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.

  • CVE-2010-2645Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Google Chrome before 5.0.375.99, when WebGL is used, allows remote attackers to cause a denial of service (out-of-bounds read) via unknown vectors.

  • CVE-2010-2479Jul 6, 2010
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-1670Jul 6, 2010
    risk 0.00cvss —epss 0.02

    Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass authentication via an empty password. …

  • CVE-2010-1669Jul 6, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2010-1668Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2010-1667Jul 6, 2010
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-2629Jul 6, 2010
    risk 0.00cvss —epss 0.01

    The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct…

  • CVE-2010-2483Jul 6, 2010
    risk 0.00cvss —epss 0.02

    The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values.

  • CVE-2010-2482Jul 6, 2010
    risk 0.04cvss —epss 0.09

    LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

  • CVE-2010-2481Jul 6, 2010
    risk 0.00cvss —epss 0.03

    The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.

  • CVE-2010-2253Jul 6, 2010
    risk 0.00cvss —epss 0.03

    lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a URL with a crafted filename or (2) a Content-Disposition header that suggests…

  • CVE-2010-2252Jul 6, 2010
    risk 0.00cvss —epss 0.04

    GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx…

  • CVE-2010-2251Jul 6, 2010
    risk 0.00cvss —epss 0.04

    The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that…

  • CVE-2010-1576Jul 6, 2010
    risk 0.00cvss —epss 0.02

    The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows…

  • CVE-2010-1575Jul 6, 2010
    risk 0.00cvss —epss 0.02

    The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted header data, as…

  • CVE-2010-1328Jul 6, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_registrese.php3 in the Services section, (3) the rubro parameter to precios.php3…

  • CVE-2010-1327Jul 6, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.

  • CVE-2010-2627Jul 2, 2010
    risk 0.03cvss —epss 0.04

    Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash)…

  • CVE-2010-2626Jul 2, 2010
    risk 0.04cvss —epss 0.13

    index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.

  • CVE-2010-2625Jul 2, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Client Service for DPM in Hitachi ServerConductor / Deployment Manager 01-00, 01-01, and 06-00 through 06-00-/A; ServerConductor / Deployment Manager Standard Edition and Enterprise Edition 07-50 through 07-55, and 07-57 through 07-59; and…

  • CVE-2010-2624Jul 2, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.

  • CVE-2010-2623Jul 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.

  • CVE-2010-2622Jul 2, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2010-2621Jul 2, 2010
    risk 0.04cvss —epss 0.11

    The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.

  • CVE-2010-2620Jul 2, 2010
    risk 0.05cvss —epss 0.30

    Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.

  • CVE-2010-2619Jul 2, 2010
    risk 0.00cvss —epss 0.00

    Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."

  • CVE-2004-2769Jul 2, 2010
    risk 0.00cvss —epss 0.01

    Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.

  • CVE-2009-4924Jul 2, 2010
    risk 0.00cvss —epss 0.01

    Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

  • CVE-2010-2549Jul 2, 2010
    risk 0.03cvss —epss 0.05

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the…