VYPR

CVEs

385,452 total · page 6962 of 7,710

  • CVE-2009-1015Jul 14, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors.

  • CVE-2009-0987Jul 14, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

  • CVE-2009-0217Jul 14, 2009
    risk 0.00cvss —epss 0.06

    The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA…

  • CVE-2009-2461Jul 14, 2009
    risk 0.00cvss —epss 0.00

    mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.

  • CVE-2009-2460Jul 14, 2009
    risk 0.00cvss —epss 0.03

    Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.

  • CVE-2009-2459Jul 14, 2009
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.

  • CVE-2009-2458Jul 14, 2009
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Sun Fire V215 Server, when using XVR-100 graphic cards on system boards with part number 375-3463 and a hardware dash level -04 or later, allows remote attackers to cause a denial of service (panic) via unknown vectors.

  • CVE-2009-2457Jul 14, 2009
    risk 0.00cvss —epss 0.02

    The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.

  • CVE-2009-2456Jul 14, 2009
    risk 0.00cvss —epss 0.03

    The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).

  • CVE-2009-2347Jul 14, 2009
    risk 0.00cvss —epss 0.04

    Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in…

  • CVE-2009-1425Jul 14, 2009
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service by triggering a stop or crash in httpd, aka PR_18770, a different vulnerability than CVE-2009-1423 and…

  • CVE-2009-1424Jul 14, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39412, a different vulnerability than CVE-2009-1423 and CVE-2009-1425.

  • CVE-2009-1423Jul 14, 2009
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.

  • CVE-2009-1422Jul 14, 2009
    risk 0.03cvss —epss 0.05

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209.

  • CVE-2009-1383Jul 14, 2009
    risk 0.00cvss —epss 0.02

    The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag.

  • CVE-2009-1382Jul 14, 2009
    risk 0.01cvss —epss 0.09

    Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.

  • CVE-2009-0692Jul 14, 2009
    risk 0.05cvss —epss 0.26

    Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

  • CVE-2009-0192Jul 14, 2009
    risk 0.04cvss —epss 0.12

    Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.

  • CVE-2009-2455Jul 14, 2009
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in webadmin/admin.php in @mail 5.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) type and (2) func parameters. NOTE: the provenance of this information is unknown; the details are obtained solely…

  • CVE-2009-2454Jul 14, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2009-2453Jul 14, 2009
    risk 0.00cvss —epss 0.01

    Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.

  • CVE-2009-2452Jul 14, 2009
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."

  • CVE-2009-2451Jul 14, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.

  • CVE-2008-6867Jul 14, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter.

  • CVE-2008-6866Jul 14, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a summary action.

  • CVE-2008-6865Jul 14, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage action.

  • CVE-2008-6864Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6863Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6862Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6861Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6860Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6859Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6858Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6857Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6856Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2008-6855Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.

  • CVE-2008-6854Jul 14, 2009
    risk 0.03cvss —epss 0.03

    Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2009-2450Jul 13, 2009
    risk 0.03cvss —epss 0.01

    The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel…

  • CVE-2009-2449Jul 13, 2009
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter.

  • CVE-2009-2448Jul 13, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2009-2447Jul 13, 2009
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter.

  • CVE-2009-2446Jul 13, 2009
    risk 0.04cvss —epss 0.11

    Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string…

  • CVE-2009-2445Jul 13, 2009
    risk 0.00cvss —epss 0.03

    Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.

  • CVE-2009-2444Jul 13, 2009
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.

  • CVE-2009-2443Jul 13, 2009
    risk 0.03cvss —epss 0.03

    Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

  • CVE-2009-2442Jul 13, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action.

  • CVE-2009-2441Jul 13, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.

  • CVE-2009-2440Jul 13, 2009
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2009-2439Jul 13, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product…

  • CVE-2009-2438Jul 13, 2009
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action. NOTE: this might overlap CVE-2008-1399.