VYPR

CVEs

385,727 total · page 6898 of 7,715

  • CVE-2010-1177Mar 29, 2010
    risk 0.04cvss —epss 0.07

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

  • CVE-2010-1176Mar 29, 2010
    risk 0.04cvss —epss 0.09

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a…

  • CVE-2010-1175Mar 29, 2010
    risk 0.04cvss —epss 0.14

    Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."

  • CVE-2010-1174Mar 29, 2010
    risk 0.03cvss —epss 0.05

    Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information.

  • CVE-2010-0452Mar 29, 2010
    risk 0.00cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-4761Mar 29, 2010
    risk 0.03cvss —epss 0.06

    Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long string in a .smi file.

  • CVE-2009-4760Mar 29, 2010
    risk 0.03cvss —epss 0.03

    Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.

  • CVE-2009-4759Mar 29, 2010
    risk 0.03cvss —epss 0.05

    Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .BMX file.

  • CVE-2009-4758Mar 29, 2010
    risk 0.03cvss —epss 0.06

    Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .YUV file.

  • CVE-2009-4757Mar 29, 2010
    risk 0.03cvss —epss 0.05

    Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: some of these details are obtained from third…

  • CVE-2009-4756Mar 29, 2010
    risk 0.04cvss —epss 0.07

    Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

  • CVE-2009-4755Mar 29, 2010
    risk 0.04cvss —epss 0.07

    Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.

  • CVE-2009-4754Mar 29, 2010
    risk 0.03cvss —epss 0.06

    Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.

  • CVE-2009-4753Mar 29, 2010
    risk 0.03cvss —epss 0.03

    Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attackers to cause a denial of service (TCP/IP outage) via long arguments to the (1) XRMD, (2) delete, (3) RNFR, or (4) RNTO command.

  • CVE-2010-1136Mar 27, 2010
    risk 0.00cvss —epss 0.02

    The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

  • CVE-2010-1135Mar 27, 2010
    risk 0.00cvss —epss 0.02

    The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.

  • CVE-2010-1134Mar 27, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.

  • CVE-2010-1133Mar 27, 2010
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.

  • CVE-2010-1132Mar 27, 2010
    risk 0.04cvss —epss 0.09

    The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

  • CVE-2010-1131Mar 27, 2010
    risk 0.03cvss —epss 0.04

    JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the substring.

  • CVE-2010-1130Mar 26, 2010
    risk 0.04cvss —epss 0.10

    session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument…

  • CVE-2010-1129Mar 26, 2010
    risk 0.00cvss —epss 0.03

    The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

  • CVE-2010-1128Mar 26, 2010
    risk 0.04cvss —epss 0.08

    The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid…

  • CVE-2010-1127Mar 26, 2010
    risk 0.01cvss —epss 0.19

    Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated…

  • CVE-2010-1126Mar 26, 2010
    risk 0.00cvss —epss 0.02

    The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.

  • CVE-2010-1125Mar 26, 2010
    risk 0.00cvss —epss 0.02

    The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls…

  • CVE-2009-4752Mar 26, 2010
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter.

  • CVE-2009-4751Mar 26, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

  • CVE-2009-4750Mar 26, 2010
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

  • CVE-2009-4749Mar 26, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x parameter to (1) message_box.php and (2) request.php.

  • CVE-2009-4748Mar 26, 2010
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

  • CVE-2009-4747Mar 26, 2010
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.

  • CVE-2009-4746Mar 26, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.

  • CVE-2009-4745Mar 26, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.

  • CVE-2009-4744Mar 26, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Contact module in Exponent CMS 0.97-GA20090213 allows remote attackers to inject arbitrary web script or HTML via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2009-4743Mar 26, 2010
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters.

  • CVE-2009-4742Mar 26, 2010
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module,…

  • CVE-2009-4741Mar 26, 2010
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors.

  • CVE-2009-4740Mar 26, 2010
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.

  • CVE-2009-4739Mar 26, 2010
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

  • CVE-2010-1124Mar 26, 2010
    risk 0.00cvss —epss 0.01

    bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM…

  • CVE-2010-1123Mar 26, 2010
    risk 0.00cvss —epss 0.00

    Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.

  • CVE-2010-0989Mar 26, 2010
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.

  • CVE-2010-0988Mar 26, 2010
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to…

  • CVE-2010-0740Mar 26, 2010
    risk 0.05cvss —epss 0.20

    The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. NOTE: some of…

  • CVE-2010-0731Mar 26, 2010
    risk 0.00cvss —epss 0.03

    The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate…

  • CVE-2010-0439Mar 26, 2010
    risk 0.00cvss —epss 0.00

    Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.

  • CVE-2009-4505Mar 26, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.

  • CVE-2010-1122Mar 25, 2010
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than…

  • CVE-2010-0628Mar 25, 2010
    risk 0.00cvss —epss 0.03

    The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an…