VYPR

CVEs

385,496 total · page 6944 of 7,710

  • CVE-2009-2206Sep 10, 2009
    risk 0.00cvss —epss 0.05

    Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted…

  • CVE-2009-2203Sep 10, 2009
    risk 0.00cvss —epss 0.06

    Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file.

  • CVE-2009-2202Sep 10, 2009
    risk 0.00cvss —epss 0.05

    Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file.

  • CVE-2008-7160Sep 10, 2009
    risk 0.00cvss —epss 0.04

    The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted…

  • CVE-2008-7159Sep 10, 2009
    risk 0.00cvss —epss 0.03

    The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu…

  • CVE-2009-3162Sep 10, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.

  • CVE-2009-3161Sep 10, 2009
    risk 0.00cvss —epss 0.02

    The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other impact via malformed data.

  • CVE-2009-3160Sep 10, 2009
    risk 0.00cvss —epss 0.02

    IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue.

  • CVE-2009-3159Sep 10, 2009
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial of service via unknown vectors.

  • CVE-2009-3158Sep 10, 2009
    risk 0.03cvss —epss 0.03

    admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.

  • CVE-2009-3157Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type.

  • CVE-2009-3156Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type…

  • CVE-2009-3155Sep 10, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

  • CVE-2009-3154Sep 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.

  • CVE-2009-3153Sep 10, 2009
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id parameter to (3)…

  • CVE-2009-3152Sep 10, 2009
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board view action.

  • CVE-2009-3151Sep 10, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.

  • CVE-2009-3150Sep 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.

  • CVE-2009-3149Sep 10, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2009-3148Sep 10, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to assignments.php.

  • CVE-2009-3147Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter.

  • CVE-2009-3146Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search_advance.php in ArticleFriend Script allows remote attackers to inject arbitrary web script or HTML via the SearchWd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2009-3051Sep 10, 2009
    risk 0.00cvss —epss 0.05

    Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to…

  • CVE-2008-7202Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2008-7201Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Lantronix MSS485-T allows remote attackers to cause a denial of service (unstable performance and service loss) via certain vulnerability scans, as demonstrated using (1) Nessus and (2) nmap.

  • CVE-2008-7200Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Double free vulnerability in Deliantra server engine before 2.4 has unknown impact and attack vectors.

  • CVE-2008-7199Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Phoenix Contact FL IL 24 BK-PAC allows remote attackers to cause a denial of service (hang) via (1) unspecified manipulations as demonstrated by a Nessus scan or (2) malformed input to TCP port 502.

  • CVE-2008-7198Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

  • CVE-2008-7197Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors.

  • CVE-2008-7196Sep 10, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability.

  • CVE-2008-7195Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server Enterprise Edition 7.0.1 for Solaris, allows attackers to cause a denial of service via unknown vectors related to SSL.

  • CVE-2008-7194Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server 5.0, 7.0, 7.0.1, and 8.0.0 for Windows, allows attackers to cause a denial of service via a crafted request.

  • CVE-2007-6730Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote router management via goform/formRmtMgt or (2) modify…

  • CVE-2007-6729Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the web management interface in the ZyXEL P-330W router allows remote attackers to inject arbitrary web script or HTML via the pingstr parameter and other unspecified vectors.

  • CVE-2009-3124Sep 9, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.

  • CVE-2009-3123Sep 9, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.

  • CVE-2009-3122Sep 9, 2009
    risk 0.00cvss —epss 0.01

    The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.

  • CVE-2009-3121Sep 9, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-3120Sep 9, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2009-3119Sep 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.

  • CVE-2009-3118Sep 9, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php,…

  • CVE-2009-3117Sep 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2009-3116Sep 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.

  • CVE-2009-3115Sep 9, 2009
    risk 0.04cvss —epss 0.11

    SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.

  • CVE-2009-3114Sep 9, 2009
    risk 0.00cvss —epss 0.02

    The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.

  • CVE-2009-2205Sep 9, 2009
    risk 0.00cvss —epss 0.02

    Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

  • CVE-2009-3113Sep 9, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.

  • CVE-2009-3112Sep 9, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.

  • CVE-2008-7193Sep 9, 2009
    risk 0.00cvss —epss 0.01

    PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php…

  • CVE-2008-7192Sep 9, 2009
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action…