VYPR

CVEs

384,396 total · page 6999 of 7,688

  • CVE-2008-5997Jan 28, 2009
    risk 0.03cvss —epss 0.03

    Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrary directories via a full pathname in the root parameter.

  • CVE-2008-5996Jan 28, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category…

  • CVE-2008-5995Jan 28, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-5994Jan 28, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2008-5993Jan 28, 2009
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the code parameter.

  • CVE-2008-5992Jan 28, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.

  • CVE-2008-5991Jan 28, 2009
    risk 0.03cvss —epss 0.06

    Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the doc parameter.

  • CVE-2008-5990Jan 28, 2009
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php.

  • CVE-2008-5989Jan 28, 2009
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

  • CVE-2008-5988Jan 28, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2009-0318Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

  • CVE-2009-0317Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function…

  • CVE-2009-0316Jan 28, 2009
    risk 0.00cvss —epss 0.03

    Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function…

  • CVE-2009-0315Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

  • CVE-2009-0314Jan 28, 2009
    risk 0.00cvss —epss 0.01

    Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

  • CVE-2008-5987Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv…

  • CVE-2008-5986Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the (1) "VST plugin with Python scripting" and (2) "VST plugin for writing score generators in Python" in Csound 5.08.2, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current…

  • CVE-2008-5985Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function…

  • CVE-2008-5984Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function…

  • CVE-2009-0313Jan 28, 2009
    risk 0.00cvss —epss 0.00

    winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

  • CVE-2008-5983Jan 28, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code…

  • CVE-2009-0312Jan 28, 2009
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.

  • CVE-2009-0042Jan 28, 2009
    risk 0.00cvss —epss 0.04

    Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote…

  • CVE-2007-2795Jan 27, 2009
    risk 0.05cvss —epss 0.24

    Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which…

  • CVE-2009-0311Jan 27, 2009
    risk 0.00cvss —epss 0.05

    The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.

  • CVE-2008-5982Jan 27, 2009
    risk 0.01cvss —epss 0.08

    Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.

  • CVE-2009-0304Jan 27, 2009
    risk 0.04cvss —epss 0.10

    The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.

  • CVE-2009-0303Jan 27, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.

  • CVE-2009-0302Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

  • CVE-2009-0301Jan 27, 2009
    risk 0.03cvss —epss 0.02

    Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.

  • CVE-2009-0299Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2009-0298Jan 27, 2009
    risk 0.03cvss —epss 0.06

    Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.

  • CVE-2009-0297Jan 27, 2009
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.

  • CVE-2009-0296Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2009-0295Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2009-0294Jan 27, 2009
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5)…

  • CVE-2009-0293Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.

  • CVE-2009-0292Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.

  • CVE-2009-0291Jan 27, 2009
    risk 0.04cvss —epss 0.07

    Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.

  • CVE-2009-0032Jan 27, 2009
    risk 0.00cvss —epss 0.00

    CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

  • CVE-2009-0290Jan 27, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI…

  • CVE-2009-0289Jan 27, 2009
    risk 0.00cvss —epss 0.02

    k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.

  • CVE-2009-0288Jan 27, 2009
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.

  • CVE-2009-0287Jan 27, 2009
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.

  • CVE-2009-0286Jan 27, 2009
    risk 0.03cvss —epss 0.06

    Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.

  • CVE-2009-0285Jan 27, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2009-0284Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2009-0283Jan 27, 2009
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2009-0282Jan 27, 2009
    risk 0.00cvss —epss 0.06

    Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request…

  • CVE-2009-0281Jan 27, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.