VYPR

CVEs

383,896 total · page 7056 of 7,678

  • CVE-2008-2838Jun 24, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

  • CVE-2008-2839Jun 24, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.

  • CVE-2008-2840Jun 24, 2008
    risk 0.00cvss —epss 0.01

    Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompage.php, (2) errors/404.php, (3) members/memberslist.php, (4)…

  • CVE-2008-2841Jun 24, 2008
    risk 0.04cvss —epss 0.15

    Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

  • CVE-2008-2306Jun 23, 2008
    risk 0.00cvss —epss 0.04

    Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.

  • CVE-2008-2307Jun 23, 2008
    risk 0.01cvss —epss 0.07

    Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving…

  • CVE-2008-2829Jun 23, 2008
    risk 0.00cvss —epss 0.05

    php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow"…

  • CVE-2008-2830Jun 23, 2008
    risk 0.03cvss —epss 0.01

    Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application,…

  • CVE-2008-1952Jun 23, 2008
    risk 0.00cvss —epss 0.00

    The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.

  • CVE-2008-2827Jun 23, 2008
    risk 0.03cvss —epss 0.01

    The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.

  • CVE-2008-2828Jun 23, 2008
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in tmsnc allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an MSN packet with a UBX command containing a large UBX payload length field.

  • CVE-2008-2813Jun 23, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

  • CVE-2008-2814Jun 23, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2008-2815Jun 23, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2816Jun 23, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

  • CVE-2008-2817Jun 23, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.

  • CVE-2008-2818Jun 23, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.

  • CVE-2008-2819Jun 23, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in BlognPlus (BURO GUN +) 2.5.4 and earlier MySQL and PostgreSQL editions allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2008-2820Jun 23, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

  • CVE-2008-2821Jun 23, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

  • CVE-2008-2822Jun 23, 2008
    risk 0.03cvss —epss 0.03

    Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD command.

  • CVE-2008-2823Jun 23, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.

  • CVE-2008-2824Jun 23, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Extensible Interface Platform in Web Services in Xerox WorkCentre 7655, 7665, and 7675 allows remote attackers to make configuration changes via unknown vectors.

  • CVE-2008-2825Jun 23, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the embedded Web Server in Xerox WorkCentre M123, M128, and 133 and WorkCentre Pro 123, 128, and 133 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-2787Jun 20, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter.

  • CVE-2008-2788Jun 20, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.

  • CVE-2008-2789Jun 20, 2008
    risk 0.05cvss —epss 0.23

    SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

  • CVE-2008-2790Jun 20, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2791Jun 20, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2792Jun 20, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter.

  • CVE-2008-2793Jun 20, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

  • CVE-2008-2794Jun 20, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

  • CVE-2008-2795Jun 20, 2008
    risk 0.04cvss —epss 0.10

    Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.

  • CVE-2008-2796Jun 20, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2008-2797Jun 20, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in MainLayout.do in ManageEngine OpUtils 5.0 allows remote attackers to inject arbitrary web script or HTML via the hostName parameter, when viewing an SNMP graph. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2008-2665Jun 20, 2008
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has…

  • CVE-2008-2666Jun 20, 2008
    risk 0.04cvss —epss 0.14

    Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok…

  • CVE-2008-2785Jun 19, 2008
    risk 0.00cvss —epss 0.05

    Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to…

  • CVE-2008-2786Jun 19, 2008
    risk 0.00cvss —epss 0.01

    Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether this is the same issue as CVE-2008-2785. A CVE identifier has been assigned for tracking purposes.

  • CVE-2008-2774Jun 19, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.

  • CVE-2008-2775Jun 19, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to execute arbitrary SQL commands via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-2776Jun 19, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-2777Jun 19, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Ortro before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-2778Jun 19, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to execute arbitrary SQL commands via the search parameter.

  • CVE-2008-2779Jun 19, 2008
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue…

  • CVE-2008-2780Jun 19, 2008
    risk 0.00cvss —epss 0.01

    The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, which allows attackers to distinguish between encrypted data and random padding at the end of the encrypted file.

  • CVE-2008-2781Jun 19, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action.

  • CVE-2008-2782Jun 19, 2008
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) library_rss.php and (2) rss.php.

  • CVE-2008-2783Jun 19, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde…

  • CVE-2008-2784Jun 19, 2008
    risk 0.00cvss —epss 0.01

    The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed…