VYPR

CVEs

384,163 total · page 7014 of 7,684

  • CVE-2008-5109Nov 25, 2008
    risk 0.00cvss —epss 0.02

    The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.

  • CVE-2008-4829Nov 25, 2008
    risk 0.01cvss —epss 0.06

    Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry, related to the http_get_pls…

  • CVE-2008-4233Nov 25, 2008
    risk 0.00cvss —epss 0.02

    Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.

  • CVE-2008-4232Nov 25, 2008
    risk 0.00cvss —epss 0.02

    Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.

  • CVE-2008-4231Nov 25, 2008
    risk 0.00cvss —epss 0.06

    Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML…

  • CVE-2008-4230Nov 25, 2008
    risk 0.00cvss —epss 0.00

    The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by reading these messages. …

  • CVE-2008-4229Nov 25, 2008
    risk 0.00cvss —epss 0.00

    Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.

  • CVE-2008-4228Nov 25, 2008
    risk 0.00cvss —epss 0.00

    The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.

  • CVE-2008-4227Nov 25, 2008
    risk 0.00cvss —epss 0.02

    Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level than was previously used, which makes it easier for remote attackers to obtain sensitive information or hijack a connection by…

  • CVE-2008-4226Nov 25, 2008
    risk 0.00cvss —epss 0.04

    Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.

  • CVE-2008-4225Nov 25, 2008
    risk 0.00cvss —epss 0.03

    Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.

  • CVE-2008-1586Nov 25, 2008
    risk 0.00cvss —epss 0.03

    ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.

  • CVE-2008-5226Nov 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.

  • CVE-2008-5225Nov 25, 2008
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under…

  • CVE-2008-5224Nov 25, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-5223Nov 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

  • CVE-2008-5222Nov 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in login.asp in Dvbbs 8.2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2008-5221Nov 25, 2008
    risk 0.03cvss —epss 0.03

    The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype…

  • CVE-2008-5220Nov 25, 2008
    risk 0.04cvss —epss 0.14

    Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/.

  • CVE-2008-5219Nov 25, 2008
    risk 0.04cvss —epss 0.07

    The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and…

  • CVE-2008-5218Nov 25, 2008
    risk 0.03cvss —epss 0.03

    ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.

  • CVE-2008-5217Nov 24, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

  • CVE-2008-5216Nov 24, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2008-5215Nov 24, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.

  • CVE-2008-5214Nov 24, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.

  • CVE-2008-5213Nov 24, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.

  • CVE-2008-5212Nov 24, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

  • CVE-2008-5211Nov 24, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.

  • CVE-2008-5210Nov 24, 2008
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4)…

  • CVE-2008-5209Nov 24, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2008-5208Nov 24, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

  • CVE-2008-5207Nov 21, 2008
    risk 0.00cvss —epss 0.01

    Multiple directory traversal vulnerabilities in Jonascms 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the taal parameter to (1) backup.php and (2) gb_voegtoe.php. NOTE: the provenance of this information is unknown; the details…

  • CVE-2008-5206Nov 21, 2008
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in modules/mod_mainmenu.php in MosXML 1 Alpha allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely…

  • CVE-2008-5205Nov 21, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.

  • CVE-2008-5204Nov 21, 2008
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2) angemeldet.php, (3)…

  • CVE-2008-5203Nov 21, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in external_vote.php in PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the l_vote_done parameter.

  • CVE-2008-5202Nov 21, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS 24a allows remote attackers to inject arbitrary web script or HTML via the conteudo parameter.

  • CVE-2008-5201Nov 21, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC…

  • CVE-2008-5200Nov 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

  • CVE-2008-5199Nov 21, 2008
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the gorumDir parameter.

  • CVE-2008-5198Nov 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.

  • CVE-2008-5197Nov 21, 2008
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.

  • CVE-2008-5196Nov 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.

  • CVE-2008-5195Nov 21, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.

  • CVE-2008-5194Nov 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-5193Nov 21, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.

  • CVE-2008-5192Nov 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2007-2641, or CVE-2007-0920.

  • CVE-2008-5191Nov 21, 2008
    risk 0.04cvss —epss 0.18

    Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.

  • CVE-2008-5190Nov 21, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter.

  • CVE-2008-5189Nov 21, 2008
    risk 0.00cvss —epss 0.02

    CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.