VYPR

CVEs

385,739 total · page 6887 of 7,715

  • CVE-2010-1599Apr 29, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter.

  • CVE-2010-1598Apr 29, 2010
    risk 0.00cvss —epss 0.02

    phpThumb.php in phpThumb() 1.7.9 and possibly other versions, when ImageMagick is installed, allows remote attackers to execute arbitrary commands via the fltr[] parameter, as discovered in the wild in April 2010. NOTE: the provenance of this information is unknown; the details…

  • CVE-2010-1597Apr 29, 2010
    risk 0.04cvss —epss 0.12

    Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long filename.

  • CVE-2010-1596Apr 28, 2010
    risk 0.00cvss —epss 0.02

    Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

  • CVE-2010-1595Apr 28, 2010
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.

  • CVE-2010-1594Apr 28, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are…

  • CVE-2010-1593Apr 28, 2010
    risk 0.00cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote…

  • CVE-2010-1592Apr 28, 2010
    risk 0.00cvss —epss 0.00

    sandra.sys 15.18.1.1 and earlier in the Sandra Device Driver in SiSoftware Sandra 16.10.2010.1 and earlier allows local users to gain privileges or cause a denial of service (system crash) via unspecified vectors involving "Model-Specific Registers."

  • CVE-2010-1591Apr 28, 2010
    risk 0.03cvss —epss 0.02

    Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4)…

  • CVE-2010-1590Apr 28, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the…

  • CVE-2010-1589Apr 28, 2010
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST…

  • CVE-2010-1588Apr 28, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via the websess parameter.

  • CVE-2010-1587Apr 28, 2010
    risk 0.02cvss —epss 0.78

    The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.

  • CVE-2010-1586Apr 28, 2010
    risk 0.04cvss —epss 0.10

    Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.

  • CVE-2010-1585Apr 28, 2010
    risk 0.00cvss —epss 0.04

    The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes…

  • CVE-2010-1429Apr 28, 2010
    risk 0.07cvss —epss 0.54

    Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query…

  • CVE-2010-1428HigKEVApr 28, 2010
    risk 0.75cvss 7.5epss 0.61

    The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive…

  • CVE-2010-1038Apr 28, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in HP System Insight Manager before 6.0 allows remote authenticated users to gain privileges via unknown vectors.

  • CVE-2010-1037Apr 28, 2010
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2010-1036Apr 28, 2010
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-0738MedKEVApr 28, 2010
    risk 0.62cvss 5.3epss 0.80

    The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this…

  • CVE-2010-1560Apr 27, 2010
    risk 0.00cvss —epss 0.02

    Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.

  • CVE-2010-1559Apr 27, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third…

  • CVE-2010-0772Apr 27, 2010
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."

  • CVE-2010-0105Apr 27, 2010
    risk 0.03cvss —epss 0.01

    The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application…

  • CVE-2009-4830Apr 27, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via unknown vectors, possibly related to www/admin/install.php, www/admin/install-plugins.php, and other www/admin/ files.

  • CVE-2009-4829Apr 27, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users with administer autologout privileges to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-4828Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an admin_created action. NOTE: some…

  • CVE-2009-4827Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.

  • CVE-2009-4826Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.

  • CVE-2009-4825Apr 27, 2010
    risk 0.03cvss —epss 0.02

    8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.

  • CVE-2009-4824Apr 27, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form."

  • CVE-2009-4823Apr 27, 2010
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.

  • CVE-2009-4822Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.

  • CVE-2009-4821Apr 27, 2010
    risk 0.00cvss —epss 0.01

    The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified…

  • CVE-2009-4820Apr 27, 2010
    risk 0.03cvss —epss 0.02

    Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb.

  • CVE-2009-4819Apr 27, 2010
    risk 0.03cvss —epss 0.03

    Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.

  • CVE-2009-4818Apr 27, 2010
    risk 0.03cvss —epss 0.04

    Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif.

  • CVE-2009-4817Apr 27, 2010
    risk 0.03cvss —epss 0.03

    Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.

  • CVE-2009-4816Apr 27, 2010
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

  • CVE-2009-4815Apr 27, 2010
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2009-4814Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.

  • CVE-2009-4813Apr 27, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.

  • CVE-2009-4812Apr 27, 2010
    risk 0.00cvss —epss 0.01

    Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message.

  • CVE-2009-4811Apr 27, 2010
    risk 0.00cvss —epss 0.03

    VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6…

  • CVE-2010-1544Apr 26, 2010
    risk 0.03cvss —epss 0.03

    micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.

  • CVE-2010-1543Apr 26, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.

  • CVE-2010-1542Apr 26, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks or (2) change…

  • CVE-2010-1541Apr 26, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.

  • CVE-2010-1540Apr 26, 2010
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. NOTE: some of these details are obtained from third party information.