VYPR

CVEs

384,113 total · page 7020 of 7,683

  • CVE-2008-4901Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2008-4900Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4899Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.

  • CVE-2008-4898Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.

  • CVE-2008-4897Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the art parameter.

  • CVE-2008-4896Nov 4, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the art parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-4895Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4894Nov 4, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory…

  • CVE-2008-4893Nov 4, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path parameter. NOTE: the…

  • CVE-2008-4892Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from…

  • CVE-2008-4891Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-4913Nov 4, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

  • CVE-2008-4912Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

  • CVE-2008-4911Nov 4, 2008
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in the data parameter.

  • CVE-2008-4910Nov 4, 2008
    risk 0.04cvss —epss 0.10

    The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.

  • CVE-2008-4909Nov 4, 2008
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in CompactCMS 1.1 and earlier allows remote attackers to perform unauthorized actions as legitimate users via unspecified vectors.

  • CVE-2008-4908Nov 4, 2008
    risk 0.00cvss —epss 0.00

    maps/Info/combine.pl in CrossFire crossfire-maps 1.11.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

  • CVE-2008-4890Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4889Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.

  • CVE-2008-4888Nov 4, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2008-4887Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: some of these details are obtained from third party…

  • CVE-2008-4886Nov 4, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.

  • CVE-2008-4885Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4884Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4883Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4882Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4881Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4880Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

  • CVE-2008-4879Nov 4, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.

  • CVE-2008-3868Nov 3, 2008
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super administrators for requests that create super administrator accounts.

  • CVE-2008-3867Nov 3, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands via the email_user_key parameter.

  • CVE-2008-4878Nov 1, 2008
    risk 0.03cvss —epss 0.04

    Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.

  • CVE-2008-4877Nov 1, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-4876Nov 1, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error…

  • CVE-2008-4875Nov 1, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for…

  • CVE-2008-4874Nov 1, 2008
    risk 0.03cvss —epss 0.04

    The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.

  • CVE-2008-4873Nov 1, 2008
    risk 0.03cvss —epss 0.05

    board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.

  • CVE-2008-4872Nov 1, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-4871Nov 1, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbitrary web script or HTML via BBcode IMG tags.

  • CVE-2008-4870Nov 1, 2008
    risk 0.00cvss —epss 0.00

    dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

  • CVE-2008-4869Nov 1, 2008
    risk 0.00cvss —epss 0.02

    FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to cause a denial of service (memory consumption) via unknown vectors, aka a "Tcp/udp memory leak."

  • CVE-2008-4868Nov 1, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."

  • CVE-2008-4867Nov 1, 2008
    risk 0.00cvss —epss 0.02

    Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.

  • CVE-2008-4866Nov 1, 2008
    risk 0.00cvss —epss 0.05

    Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.

  • CVE-2008-4865Nov 1, 2008
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been…

  • CVE-2008-4864Nov 1, 2008
    risk 0.05cvss —epss 0.21

    Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer…

  • CVE-2008-4863Nov 1, 2008
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.

  • CVE-2008-4309HigOct 31, 2008
    risk 0.42cvss 7.5epss 0.05

    Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a…

  • CVE-2008-4811Oct 31, 2008
    risk 0.00cvss —epss 0.02

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character.

  • CVE-2008-4810Oct 31, 2008
    risk 0.00cvss —epss 0.02

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka "php executed in templates;" and (2) a double quoted…