VYPR

CVEs

383,957 total · page 7033 of 7,680

  • CVE-2008-3609Sep 16, 2008
    risk 0.00cvss —epss 0.00

    The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.

  • CVE-2008-3608Sep 16, 2008
    risk 0.00cvss —epss 0.03

    ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.

  • CVE-2008-2332Sep 16, 2008
    risk 0.00cvss —epss 0.03

    ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.

  • CVE-2008-2331Sep 16, 2008
    risk 0.00cvss —epss 0.01

    Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an…

  • CVE-2008-2330Sep 16, 2008
    risk 0.00cvss —epss 0.00

    slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."

  • CVE-2008-2329Sep 16, 2008
    risk 0.00cvss —epss 0.00

    Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.

  • CVE-2008-2312Sep 16, 2008
    risk 0.00cvss —epss 0.00

    Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.

  • CVE-2008-2305Sep 16, 2008
    risk 0.00cvss —epss 0.05

    Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."

  • CVE-2008-4110Sep 16, 2008
    risk 0.01cvss —epss 0.18

    Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second…

  • CVE-2008-2437Sep 16, 2008
    risk 0.01cvss —epss 0.07

    Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long…

  • CVE-2008-4095Sep 16, 2008
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

  • CVE-2008-4093Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.

  • CVE-2008-4092Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.

  • CVE-2008-4091Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

  • CVE-2008-4090Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672.

  • CVE-2008-4089Sep 15, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

  • CVE-2008-4088Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

  • CVE-2008-4087Sep 15, 2008
    risk 0.03cvss —epss 0.03

    Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field.

  • CVE-2008-4086Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

  • CVE-2008-4085Sep 15, 2008
    risk 0.00cvss —epss 0.00

    plaiter in Plait before 1.6 allows local users to overwrite arbitrary files via a symlink attack on (1) cut.$$, (2) head.$$, (3) awk.$$, and (4) ps.$$ temporary files in /tmp/.

  • CVE-2008-4084Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.

  • CVE-2008-4083Sep 15, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. NOTE: some of these details are obtained from third party…

  • CVE-2008-4082Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.

  • CVE-2008-4081Sep 15, 2008
    risk 0.03cvss —epss 0.03

    admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.

  • CVE-2008-4080Sep 15, 2008
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these…

  • CVE-2008-4079Sep 15, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Solution allows remote attackers to inject arbitrary web script or HTML via…

  • CVE-2008-4078Sep 15, 2008
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2008-4077Sep 15, 2008
    risk 0.00cvss —epss 0.03

    The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.

  • CVE-2008-4076Sep 15, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in (1) Tor World Tor Board 1.3 and earlier, (2) Topics BBS 1.11 and earlier, (3) Simple BBS 1.86 and earlier, and (4) Interactive BBS 1.57 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors,…

  • CVE-2008-4075Sep 15, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.

  • CVE-2008-4074Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

  • CVE-2008-4073Sep 15, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.

  • CVE-2008-4072Sep 15, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.

  • CVE-2008-4071Sep 15, 2008
    risk 0.04cvss —epss 0.18

    A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.

  • CVE-2008-3889Sep 12, 2008
    risk 0.00cvss —epss 0.01

    Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a…

  • CVE-2008-3824Sep 12, 2008
    risk 0.03cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as…

  • CVE-2008-3823Sep 12, 2008
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.

  • CVE-2008-3529Sep 12, 2008
    risk 0.05cvss —epss 0.23

    Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

  • CVE-2008-3274Sep 12, 2008
    risk 0.00cvss —epss 0.02

    The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.

  • CVE-2008-2932Sep 12, 2008
    risk 0.00cvss —epss 0.03

    Heap-based buffer overflow in Red Hat adminutil 1.1.6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via % (percent) encoded HTTP input to unspecified CGI scripts in Fedora Directory Server. NOTE: this vulnerability exists…

  • CVE-2008-4057Sep 11, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Objective Development Sharity 3 before 3.5 has unknown impact and attack vectors, related to a "serious security problem."

  • CVE-2008-4056Sep 11, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-4055Sep 11, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.

  • CVE-2008-4054Sep 11, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-4053Sep 11, 2008
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.

  • CVE-2008-4052Sep 11, 2008
    risk 0.00cvss —epss 0.00

    Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of service (crash) or gain privileges via unspecified vectors.

  • CVE-2008-4051Sep 11, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-4050Sep 11, 2008
    risk 0.04cvss —epss 0.07

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.

  • CVE-2008-4049Sep 11, 2008
    risk 0.03cvss —epss 0.04

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method.

  • CVE-2008-4048Sep 11, 2008
    risk 0.04cvss —epss 0.07

    Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.