VYPR

CVEs

384,102 total · page 7021 of 7,683

  • CVE-2008-4799Oct 31, 2008
    risk 0.00cvss —epss 0.02

    pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read.

  • CVE-2008-4798Oct 30, 2008
    risk 0.00cvss —epss 0.04

    The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl module and accessing it via a crafted URL.

  • CVE-2008-4797Oct 30, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Arihiro Kurata Kantan WEB Server 1.8 and earlier allows remote attackers to read arbitrary files via unknown vectors.

  • CVE-2008-4796Oct 30, 2008
    risk 0.00cvss —epss 0.09

    The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell…

  • CVE-2008-4795Oct 30, 2008
    risk 0.03cvss —epss 0.04

    The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

  • CVE-2008-4794Oct 30, 2008
    risk 0.00cvss —epss 0.04

    Opera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different vulnerability than CVE-2008-4696.

  • CVE-2008-2238Oct 30, 2008
    risk 0.01cvss —epss 0.07

    Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

  • CVE-2008-2237Oct 30, 2008
    risk 0.00cvss —epss 0.06

    Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.

  • CVE-2007-6021Oct 30, 2008
    risk 0.01cvss —epss 0.08

    Heap-based buffer overflow in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure.

  • CVE-2007-5394Oct 30, 2008
    risk 0.01cvss —epss 0.08

    Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a .PMD file with a crafted font structure, a different vulnerability than CVE-2007-5169 and CVE-2007-6432.

  • CVE-2008-4793Oct 29, 2008
    risk 0.00cvss —epss 0.02

    The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors related to contributed modules.

  • CVE-2008-4792Oct 29, 2008
    risk 0.00cvss —epss 0.01

    The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

  • CVE-2008-4791Oct 29, 2008
    risk 0.00cvss —epss 0.02

    The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

  • CVE-2008-4790Oct 29, 2008
    risk 0.00cvss —epss 0.01

    The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

  • CVE-2008-4789Oct 29, 2008
    risk 0.00cvss —epss 0.01

    The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

  • CVE-2008-4788Oct 29, 2008
    risk 0.01cvss —epss 0.09

    Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote attackers to spoof the address bar via a URL with a domain name that differs from an important domain name only in these characters, as demonstrated by using…

  • CVE-2008-4787Oct 29, 2008
    risk 0.04cvss —epss 0.14

    Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related…

  • CVE-2008-4786Oct 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2008-4785Oct 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4784Oct 29, 2008
    risk 0.03cvss —epss 0.03

    aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.

  • CVE-2008-4783Oct 29, 2008
    risk 0.03cvss —epss 0.03

    tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."

  • CVE-2008-4782Oct 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

  • CVE-2008-4781Oct 29, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langage parameter.

  • CVE-2008-4780Oct 29, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the padmin parameter.

  • CVE-2008-4779Oct 29, 2008
    risk 0.08cvss —epss 0.65

    Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.

  • CVE-2008-4778Oct 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.

  • CVE-2008-4777Oct 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showTests task.

  • CVE-2008-4776Oct 28, 2008
    risk 0.00cvss —epss 0.01

    libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

  • CVE-2008-4775Oct 28, 2008
    risk 0.03cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than…

  • CVE-2008-4774Oct 28, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.

  • CVE-2008-4773Oct 28, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via a .. (dot dot) in the theme parameter.

  • CVE-2008-4772Oct 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.

  • CVE-2008-4771Oct 28, 2008
    risk 0.04cvss —epss 0.07

    Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly…

  • CVE-2008-4769Oct 28, 2008
    risk 0.04cvss —epss 0.09

    Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details…

  • CVE-2008-4768Oct 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2008-4767Oct 28, 2008
    risk 0.03cvss —epss 0.04

    Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3) .txt extensions, then accessing it via a direct request to the file. NOTE: the provenance of…

  • CVE-2008-4766Oct 28, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-4765Oct 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

  • CVE-2008-4764Oct 28, 2008
    risk 0.04cvss —epss 0.17

    Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.

  • CVE-2008-4763Oct 28, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in sample.php in WiKID wClient-PHP 3.0-2 and earlier allow remote attackers to inject arbitrary web script or HTML via the PHP_SELF variable.

  • CVE-2008-4762Oct 28, 2008
    risk 0.04cvss —epss 0.14

    Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters.

  • CVE-2008-4761Oct 28, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the…

  • CVE-2008-4760Oct 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4759Oct 28, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the id parameter.

  • CVE-2008-4758Oct 28, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.

  • CVE-2008-4757Oct 28, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev parameter to (d) prest_detail.php.

  • CVE-2008-4756Oct 28, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.

  • CVE-2008-4755Oct 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4754Oct 27, 2008
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.

  • CVE-2008-4753Oct 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.