VYPR

CVEs

385,711 total · page 6903 of 7,715

  • CVE-2010-0124Mar 15, 2010
    risk 0.00cvss —epss 0.00

    Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

  • CVE-2010-0123Mar 15, 2010
    risk 0.00cvss —epss 0.01

    The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."

  • CVE-2010-0122Mar 15, 2010
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.

  • CVE-2010-0048HigMar 15, 2010
    risk 0.58cvss 8.8epss 0.05

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.

  • CVE-2010-0047HigMar 15, 2010
    risk 0.58cvss 8.8epss 0.05

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."

  • CVE-2010-0046Mar 15, 2010
    risk 0.00cvss —epss 0.06

    The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.

  • CVE-2010-0045Mar 15, 2010
    risk 0.00cvss —epss 0.04

    Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.

  • CVE-2010-0044Mar 15, 2010
    risk 0.00cvss —epss 0.02

    PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

  • CVE-2010-0043Mar 15, 2010
    risk 0.00cvss —epss 0.06

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.

  • CVE-2010-0042Mar 15, 2010
    risk 0.00cvss —epss 0.03

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.

  • CVE-2010-0041Mar 15, 2010
    risk 0.00cvss —epss 0.03

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.

  • CVE-2010-0040Mar 15, 2010
    risk 0.01cvss —epss 0.06

    Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.

  • CVE-2009-4001Mar 15, 2010
    risk 0.00cvss —epss 0.05

    Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.

  • CVE-2010-0962Mar 10, 2010
    risk 0.00cvss —epss 0.01

    The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via…

  • CVE-2010-0961Mar 10, 2010
    risk 0.00cvss —epss 0.00

    Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

  • CVE-2010-0960Mar 10, 2010
    risk 0.00cvss —epss 0.00

    Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

  • CVE-2010-0959Mar 10, 2010
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.

  • CVE-2010-0806HigKEVMar 10, 2010
    risk 0.79cvss 8.8epss 0.82

    Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the…

  • CVE-2010-0447Mar 10, 2010
    risk 0.00cvss —epss 0.05

    The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.

  • CVE-2010-0265Mar 10, 2010
    risk 0.05cvss —epss 0.27

    Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."

  • CVE-2010-0264Mar 10, 2010
    risk 0.02cvss —epss 0.21

    Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry…

  • CVE-2010-0263Mar 10, 2010
    risk 0.02cvss —epss 0.26

    Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not…

  • CVE-2010-0262Mar 10, 2010
    risk 0.02cvss —epss 0.21

    Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel…

  • CVE-2010-0261Mar 10, 2010
    risk 0.02cvss —epss 0.23

    Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up…

  • CVE-2010-0260Mar 10, 2010
    risk 0.02cvss —epss 0.23

    Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in…

  • CVE-2010-0258HigMar 10, 2010
    risk 0.56cvss 7.8epss 0.61

    Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly…

  • CVE-2010-0257Mar 10, 2010
    risk 0.01cvss —epss 0.19

    Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."

  • CVE-2009-4697Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter in a ulist action and the (2) fid parameter in a view_forum action.

  • CVE-2009-4696Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.

  • CVE-2009-4695Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.

  • CVE-2009-4694Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the fid parameter in a view_forum action. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2009-4693Mar 10, 2010
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG parameter to (1) en.inc.php, (2) hu.inc.php, (3) no.inc.php, (4) ro.inc.php, and (5) ru.inc.php in language/.

  • CVE-2009-4692Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the pr parameter in a ulist action.

  • CVE-2009-4691Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in addlink.php in Classified Linktrader Script allows remote attackers to execute arbitrary SQL commands via the slctCategories parameter.

  • CVE-2009-4690Mar 10, 2010
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rate.php and (2) postcomments.php.

  • CVE-2009-4689Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2009-4688Mar 10, 2010
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.

  • CVE-2009-4687Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter.

  • CVE-2009-4686Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the red_url parameter.

  • CVE-2009-4685Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.

  • CVE-2009-4684Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter.

  • CVE-2009-4683Mar 10, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.

  • CVE-2009-4682Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.

  • CVE-2009-4681Mar 10, 2010
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to inject arbitrary web script or HTML via the st parameter.

  • CVE-2009-4680Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL commands via the st parameter.

  • CVE-2010-0958Mar 10, 2010
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter. NOTE: some of these…

  • CVE-2010-0957Mar 10, 2010
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter.

  • CVE-2010-0956Mar 10, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2010-0955Mar 10, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-0954Mar 10, 2010
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.