VYPR

CVEs

383,870 total · page 7078 of 7,678

  • CVE-2008-1634Apr 2, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in JV2 Folder Gallery 3.1 allows remote attackers to inject arbitrary web script or HTML via the image parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-1635Apr 2, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.

  • CVE-2008-1636Apr 2, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in JV2 Quick Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-1637Apr 2, 2008
    risk 0.00cvss —epss 0.04

    PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external…

  • CVE-2008-1638Apr 2, 2008
    risk 0.00cvss —epss 0.00

    Nik Sharpener Pro, possibly 2.0, uses world-writable permissions for plug-in files, which allows local users to gain privileges by replacing a plug-in with a Trojan horse.

  • CVE-2008-1639Apr 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.

  • CVE-2008-1640Apr 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the view_id parameter in an ansicht action.

  • CVE-2008-1641Apr 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.

  • CVE-2008-1642Apr 2, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2008-1643Apr 2, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.7 SP5 and earlier and 8.8 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2008-1644Apr 2, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-1645Apr 2, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter.

  • CVE-2008-1646Apr 2, 2008
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.

  • CVE-2008-1647Apr 2, 2008
    risk 0.04cvss —epss 0.07

    The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these…

  • CVE-2008-1648Apr 2, 2008
    risk 0.00cvss —epss 0.02

    Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.

  • CVE-2008-1649Apr 2, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.

  • CVE-2008-1650Apr 2, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action.

  • CVE-2008-1651Apr 2, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

  • CVE-2008-1652Apr 2, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in the _serve_request_multiple function in lib/Perlbal/ClientHTTPBase.pm in Perlbal before 1.70, when concat get is enabled, allows remote attackers to read arbitrary files in a parent directory via a directory traversal sequence in an…

  • CVE-2008-1653Apr 2, 2008
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in index.php in Sava's Link Manager 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the q parameter. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2008-1614Apr 2, 2008
    risk 0.00cvss —epss 0.00

    suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privileges.

  • CVE-2008-1619Apr 2, 2008
    risk 0.00cvss —epss 0.01

    The ssm_i emulation in Xen 5.1 on IA64 architectures allows attackers to cause a denial of service (dom0 panic) via certain traffic, as demonstrated using an FTP stress test tool.

  • CVE-2008-1515Apr 1, 2008
    risk 0.00cvss —epss 0.02

    The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."

  • CVE-2008-1612Apr 1, 2008
    risk 0.00cvss —epss 0.02

    The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for…

  • CVE-2008-1603Apr 1, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in GNB DesignForm before 3.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the email form.

  • CVE-2008-1604Apr 1, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in PerlMailer before 3.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-1605Apr 1, 2008
    risk 0.03cvss —epss 0.02

    The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.

  • CVE-2008-1606Apr 1, 2008
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the…

  • CVE-2008-1607Apr 1, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbitrary SQL commands via the haber parameter.

  • CVE-2008-1608Apr 1, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in postview.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter, a different vector than CVE-2008-0363 and CVE-2006-0583.

  • CVE-2008-1609Apr 1, 2008
    risk 0.07cvss —epss 0.44

    Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php, (b) headlines.php, and (c) main.php in forum/, and (2) main_dir parameter…

  • CVE-2008-1610Apr 1, 2008
    risk 0.07cvss —epss 0.54

    Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request.

  • CVE-2008-1611Apr 1, 2008
    risk 0.08cvss —epss 0.68

    Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request.

  • CVE-2008-0211Mar 31, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.

  • CVE-2008-0706Mar 31, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.

  • CVE-2008-1591Mar 31, 2008
    risk 0.03cvss —epss 0.01

    The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as…

  • CVE-2008-1592Mar 31, 2008
    risk 0.00cvss —epss 0.00

    MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway…

  • CVE-2008-1593Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably…

  • CVE-2008-1594Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a…

  • CVE-2008-1595Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.

  • CVE-2008-1596Mar 31, 2008
    risk 0.00cvss —epss 0.00

    Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a…

  • CVE-2008-1597Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

  • CVE-2008-1598Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.

  • CVE-2008-1599Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.

  • CVE-2008-1600Mar 31, 2008
    risk 0.00cvss —epss 0.00

    The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.

  • CVE-2008-1601Mar 31, 2008
    risk 0.00cvss —epss 0.00

    Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.

  • CVE-2008-1560Mar 31, 2008
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.asp.

  • CVE-2008-1561Mar 31, 2008
    risk 0.04cvss —epss 0.09

    Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

  • CVE-2008-1562Mar 31, 2008
    risk 0.07cvss —epss 0.51

    The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.

  • CVE-2008-1563Mar 31, 2008
    risk 0.03cvss —epss 0.04

    The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.