VYPR

CVEs

384,326 total · page 7009 of 7,687

  • CVE-2008-5510Dec 17, 2008
    risk 0.00cvss —epss 0.02

    The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

  • CVE-2008-5508Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing…

  • CVE-2008-5507Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target…

  • CVE-2008-5506Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a…

  • CVE-2008-5505Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

  • CVE-2008-5504Dec 17, 2008
    risk 0.00cvss —epss 0.03

    Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

  • CVE-2008-5503Dec 17, 2008
    risk 0.00cvss —epss 0.02

    The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other…

  • CVE-2008-5502Dec 17, 2008
    risk 0.00cvss —epss 0.02

    The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar…

  • CVE-2008-5501Dec 17, 2008
    risk 0.00cvss —epss 0.03

    The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

  • CVE-2008-5500Dec 17, 2008
    risk 0.00cvss —epss 0.03

    The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a…

  • CVE-2008-5662Dec 17, 2008
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in Sun Java Wireless Toolkit (WTK) for CLDC 2.5.2 and earlier allow downloaded programs to execute arbitrary code via unknown vectors.

  • CVE-2008-5661Dec 17, 2008
    risk 0.00cvss —epss 0.02

    The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.

  • CVE-2008-5660Dec 17, 2008
    risk 0.04cvss —epss 0.09

    Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

  • CVE-2008-5659Dec 17, 2008
    risk 0.03cvss —epss 0.03

    The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this class for randomness, as…

  • CVE-2008-5658Dec 17, 2008
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.

  • CVE-2008-5657Dec 17, 2008
    risk 0.00cvss —epss 0.02

    CRLF injection vulnerability in Quassel Core before 0.3.0.3 allows remote attackers to spoof IRC messages as other users via a crafted CTCP message.

  • CVE-2008-5656Dec 17, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the frontend plugin for the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2008-5655Dec 17, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b)…

  • CVE-2008-5654Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344. NOTE: some of…

  • CVE-2008-5653Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third…

  • CVE-2008-5652Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third…

  • CVE-2008-5651Dec 17, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter.

  • CVE-2008-5650Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter.

  • CVE-2008-5649Dec 17, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2008-5648Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the admin_username parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5647Dec 17, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack vectors.

  • CVE-2008-5646Dec 17, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to "certain wiki markup."

  • CVE-2008-5645Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in the media server in Orb Networks Orb before 2.01.0022 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP GET request.

  • CVE-2008-5644Dec 17, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2008-5643Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to index.php.

  • CVE-2008-5642Dec 17, 2008
    risk 0.04cvss —epss 0.09

    Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cms_language cookie.

  • CVE-2008-5641Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

  • CVE-2008-5640Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

  • CVE-2008-5639Dec 17, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via a .. (dot dot) in the m parameter.

  • CVE-2008-5638Dec 17, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.

  • CVE-2008-5637Dec 17, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter.

  • CVE-2008-5636Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2008-5635Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5634Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5633Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5632Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5631Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5630Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute arbitrary SQL commands via the umprof_status parameter.

  • CVE-2008-5629Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a play action.

  • CVE-2008-5628Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter.

  • CVE-2008-5627Dec 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter (aka Email field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5626Dec 17, 2008
    risk 0.06cvss —epss 0.36

    XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument.

  • CVE-2008-5625Dec 17, 2008
    risk 0.04cvss —epss 0.07

    PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.

  • CVE-2008-5624Dec 17, 2008
    risk 0.00cvss —epss 0.02

    PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as…

  • CVE-2008-5558Dec 17, 2008
    risk 0.00cvss —epss 0.02

    Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname…