VYPR

CVEs

383,898 total · page 7053 of 7,678

  • CVE-2008-2967Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to login.php and the (2) glb_sid parameter to hta/htmlarea.js.php, and…

  • CVE-2008-2968Jul 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in rating.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

  • CVE-2008-2969Jul 2, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.

  • CVE-2008-2970Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.

  • CVE-2008-2971Jul 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in links-extern.php in CiBlog 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2972Jul 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action.

  • CVE-2008-2973Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters.

  • CVE-2008-2974Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter.

  • CVE-2008-2975Jul 2, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

  • CVE-2008-2976Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) language parameter to (a) include_me.php, (b) admin/ajax.php, and (c)…

  • CVE-2008-2977Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_connection parameter to (1) edit_top_feature.php and (2) edit_topics_feature.php in phpi/.

  • CVE-2008-2978Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the prefix parameter.

  • CVE-2008-2979Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web script or HTML via the (1) top_page and (2) end_page parameters.

  • CVE-2008-2980Jul 2, 2008
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to…

  • CVE-2008-2981Jul 2, 2008
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the thumb_template parameter.

  • CVE-2008-2982Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a)…

  • CVE-2008-2983Jul 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2984Jul 2, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.

  • CVE-2008-2985Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.

  • CVE-2008-2986Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.

  • CVE-2008-2987Jul 2, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php, and (3) admin_edit_topmenu.php in admin/.

  • CVE-2008-2988Jul 2, 2008
    risk 0.00cvss —epss 0.02

    Unrestricted file upload vulnerability in admin/upload.php in Benja CMS 0.1 allows remote attackers to upload and execute arbitrary PHP files via unspecified vectors, followed by a direct request to the file in billeder/.

  • CVE-2008-2989Jul 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter.

  • CVE-2008-2990Jul 2, 2008
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter.

  • CVE-2008-2372Jul 2, 2008
    risk 0.00cvss —epss 0.00

    The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."

  • CVE-2008-2826Jul 2, 2008
    risk 0.00cvss —epss 0.00

    Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via…

  • CVE-2008-2953Jul 1, 2008
    risk 0.00cvss —epss 0.03

    Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via "partial file list requests" that trigger a NULL pointer dereference.

  • CVE-2008-2954Jul 1, 2008
    risk 0.00cvss —epss 0.04

    client/NmdcHub.cpp in Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via an empty private message, which triggers an out-of-bounds read.

  • CVE-2008-2955Jul 1, 2008
    risk 0.04cvss —epss 0.07

    Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.

  • CVE-2008-2956Jul 1, 2008
    risk 0.00cvss —epss 0.02

    Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML documents. NOTE: this issue has been disputed by the upstream vendor, who states: "I was never able to identify a scenario under…

  • CVE-2008-2957Jul 1, 2008
    risk 0.00cvss —epss 0.02

    The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.

  • CVE-2008-2958Jul 1, 2008
    risk 0.00cvss —epss 0.00

    Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.

  • CVE-2008-2952Jul 1, 2008
    risk 0.04cvss —epss 0.13

    liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.

  • CVE-2008-2309Jul 1, 2008
    risk 0.00cvss —epss 0.03

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature…

  • CVE-2008-2310Jul 1, 2008
    risk 0.00cvss —epss 0.03

    Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.

  • CVE-2008-2311Jul 1, 2008
    risk 0.00cvss —epss 0.03

    Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.

  • CVE-2008-2313Jul 1, 2008
    risk 0.00cvss —epss 0.00

    Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.

  • CVE-2008-2314Jul 1, 2008
    risk 0.00cvss —epss 0.00

    Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.

  • CVE-2008-2308Jul 1, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount…

  • CVE-2008-0598Jun 30, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.

  • CVE-2008-2462Jun 30, 2008
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

  • CVE-2008-2729Jun 30, 2008
    risk 0.00cvss —epss 0.01

    arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.

  • CVE-2008-2945Jun 30, 2008
    risk 0.00cvss —epss 0.03

    Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related…

  • CVE-2008-2946Jun 30, 2008
    risk 0.00cvss —epss 0.03

    The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.

  • CVE-2008-2947Jun 30, 2008
    risk 0.02cvss —epss 0.25

    Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to…

  • CVE-2008-2948Jun 30, 2008
    risk 0.05cvss —epss 0.25

    Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown…

  • CVE-2008-2949Jun 30, 2008
    risk 0.05cvss —epss 0.20

    Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown…

  • CVE-2008-2365Jun 30, 2008
    risk 0.03cvss —epss 0.01

    Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a…

  • CVE-2008-2943Jun 30, 2008
    risk 0.03cvss —epss 0.02

    Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP…

  • CVE-2008-2944Jun 30, 2008
    risk 0.00cvss —epss 0.00

    Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB testsuite, a different…