VYPR

CVEs

383,885 total · page 7062 of 7,678

  • CVE-2008-1580Jun 2, 2008
    risk 0.00cvss —epss 0.01

    CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web server's certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use…

  • CVE-2008-2098Jun 2, 2008
    risk 0.00cvss —epss 0.00

    Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used,…

  • CVE-2008-2099Jun 2, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.

  • CVE-2008-2359Jun 2, 2008
    risk 0.00cvss —epss 0.00

    The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration.

  • CVE-2008-2363Jun 2, 2008
    risk 0.00cvss —epss 0.06

    The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based…

  • CVE-2008-2426Jun 2, 2008
    risk 0.00cvss —epss 0.06

    Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in…

  • CVE-2008-2511Jun 2, 2008
    risk 0.04cvss —epss 0.10

    Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the…

  • CVE-2008-2512Jun 2, 2008
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2008-2513Jun 2, 2008
    risk 0.00cvss —epss 0.00

    Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.

  • CVE-2008-2514Jun 2, 2008
    risk 0.00cvss —epss 0.00

    Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.

  • CVE-2008-2515Jun 2, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."

  • CVE-2008-2501May 29, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.

  • CVE-2008-2502May 29, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the web server in eMule X-Ray before 1.4 allows remote attackers to trigger memory corruption via unknown attack vectors.

  • CVE-2008-2503May 29, 2008
    risk 0.00cvss —epss 0.01

    Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.

  • CVE-2008-2504May 29, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to netbutik.php and the (2) id parameter to product.php.

  • CVE-2008-2505May 29, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in result.php in Simpel Side Weblosning 1 through 4 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2008-2506May 29, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Simpel Side Weblosning 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) mainid and (2) id parameters to index2.php.

  • CVE-2008-2507May 29, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action.

  • CVE-2008-2508May 29, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.

  • CVE-2008-2509May 29, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.

  • CVE-2008-2510May 29, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.

  • CVE-2008-0891May 29, 2008
    risk 0.00cvss —epss 0.04

    Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.

  • CVE-2008-0955May 29, 2008
    risk 0.06cvss —epss 0.41

    Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.

  • CVE-2008-0958May 29, 2008
    risk 0.01cvss —epss 0.08

    Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2008-0959May 29, 2008
    risk 0.00cvss —epss 0.06

    Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter…

  • CVE-2008-1105May 29, 2008
    risk 0.09cvss —epss 0.69

    Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.

  • CVE-2008-1672May 29, 2008
    risk 0.00cvss —epss 0.05

    OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.

  • CVE-2008-2054May 29, 2008
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.

  • CVE-2008-2137May 29, 2008
    risk 0.00cvss —epss 0.00

    The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap…

  • CVE-2008-2157May 29, 2008
    risk 0.06cvss —epss 0.36

    robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands via an unspecified string field in a packet to TCP port 3500.

  • CVE-2008-2158May 29, 2008
    risk 0.08cvss —epss 0.58

    Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary code via crafted TCP packets to port 41025.

  • CVE-2008-2499May 29, 2008
    risk 0.09cvss —epss 0.77

    Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.

  • CVE-2008-2500May 29, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-2477May 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2008-2478May 28, 2008
    risk 0.03cvss —epss 0.04

    scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this,…

  • CVE-2008-2479May 28, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.

  • CVE-2008-2480May 28, 2008
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter.

  • CVE-2008-2481May 28, 2008
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.

  • CVE-2008-2482May 28, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter in a go action.

  • CVE-2008-2483May 28, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the op parameter.

  • CVE-2008-2484May 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the email parameter.

  • CVE-2008-2485May 28, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the URL redirection script (inc/url_redirection.inc.php) in PCPIN Chat before 6.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2008-2486May 28, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in eMule Plus before 1.2d has unknown impact and attack vectors related to "staticservers.dat processing."

  • CVE-2008-2487May 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.

  • CVE-2008-2488May 28, 2008
    risk 0.03cvss —epss 0.02

    admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.

  • CVE-2008-2489May 28, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Library for Frontend Plugins (aka sg_zfelib) extension 1.1.512 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified "user input."

  • CVE-2008-2490May 28, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the KJ Image Lightbox 2 (aka kj_imagelightbox2) extension 1.4.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified "user input."

  • CVE-2008-2491May 28, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2008-2492May 28, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp.

  • CVE-2008-2493May 28, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML via the review parameter.