VYPR

CVEs

385,452 total · page 6963 of 7,710

  • CVE-2009-2437Jul 13, 2009
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.

  • CVE-2009-2436Jul 13, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

  • CVE-2009-2435Jul 13, 2009
    risk 0.00cvss —epss 0.01

    The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

  • CVE-2009-2434Jul 13, 2009
    risk 0.00cvss —epss 0.00

    Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

  • CVE-2009-2433Jul 10, 2009
    risk 0.05cvss —epss 0.19

    Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.

  • CVE-2009-2432Jul 10, 2009
    risk 0.00cvss —epss 0.03

    WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.

  • CVE-2009-2431Jul 10, 2009
    risk 0.00cvss —epss 0.03

    WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

  • CVE-2009-2336Jul 10, 2009
    risk 0.00cvss —epss 0.05

    The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the…

  • CVE-2009-2335Jul 10, 2009
    risk 0.03cvss —epss 0.85

    WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue,…

  • CVE-2009-2334Jul 10, 2009
    risk 0.04cvss —epss 0.06

    wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify…

  • CVE-2009-2430Jul 10, 2009
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.

  • CVE-2009-2429Jul 10, 2009
    risk 0.00cvss —epss 0.00

    SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2009-2428Jul 10, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors.

  • CVE-2009-2427Jul 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter.

  • CVE-2009-2426Jul 10, 2009
    risk 0.00cvss —epss 0.02

    The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via…

  • CVE-2009-2425Jul 10, 2009
    risk 0.00cvss —epss 0.03

    Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.

  • CVE-2009-2424Jul 10, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

  • CVE-2009-2423Jul 10, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.

  • CVE-2009-2422CriJul 10, 2009
    risk 0.64cvss 9.8epss 0.03

    The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers…

  • CVE-2009-2386Jul 10, 2009
    risk 0.03cvss —epss 0.05

    Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.

  • CVE-2009-1891Jul 10, 2009
    risk 0.01cvss —epss 0.17

    The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

  • CVE-2009-1725Jul 9, 2009
    risk 0.00cvss —epss 0.06

    WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows…

  • CVE-2009-1724Jul 9, 2009
    risk 0.03cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top…

  • CVE-2009-0667Jul 9, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.

  • CVE-2009-2421Jul 9, 2009
    risk 0.00cvss —epss 0.03

    The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an…

  • CVE-2009-2420Jul 9, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue…

  • CVE-2009-2419Jul 9, 2009
    risk 0.04cvss —epss 0.09

    Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a…

  • CVE-2009-2403Jul 9, 2009
    risk 0.04cvss —epss 0.07

    Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.

  • CVE-2009-2402Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355.

  • CVE-2009-2401Jul 9, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post.

  • CVE-2009-2400Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2009-2399Jul 9, 2009
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

  • CVE-2009-2398Jul 9, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.

  • CVE-2009-2397Jul 9, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

  • CVE-2009-2396Jul 9, 2009
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

  • CVE-2009-2395Jul 9, 2009
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.

  • CVE-2009-2394Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

  • CVE-2009-2393Jul 9, 2009
    risk 0.03cvss —epss 0.02

    admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.

  • CVE-2009-2392Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter.

  • CVE-2009-2391Jul 9, 2009
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.

  • CVE-2009-2390Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php.

  • CVE-2009-2389Jul 9, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

  • CVE-2009-2388Jul 9, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2009-2387Jul 9, 2009
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the proc filesystem in Sun OpenSolaris snv_49 through snv_109 allows local users to cause a denial of service (deadlock and panic) via unknown vectors, related to the ldt_rewrite_syscall function.

  • CVE-2009-2385Jul 8, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of…

  • CVE-2009-2384Jul 8, 2009
    risk 0.03cvss —epss 0.06

    Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.

  • CVE-2009-2383Jul 8, 2009
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the guid parameter.

  • CVE-2009-2382CriJul 8, 2009
    risk 0.67cvss 9.8epss 0.06

    admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.

  • CVE-2009-2381Jul 8, 2009
    risk 0.00cvss —epss 0.01

    Gizmo 3.1.0.79 on Linux does not verify a server's SSL certificate, which allows remote servers to obtain the credentials of arbitrary users via a spoofed certificate.

  • CVE-2009-2380Jul 8, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable.