VYPR

CVEs

383,797 total · page 7089 of 7,676

  • CVE-2008-0935Feb 25, 2008
    risk 0.08cvss —epss 0.65

    Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.

  • CVE-2008-0936Feb 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

  • CVE-2008-0937Feb 25, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.

  • CVE-2008-0938Feb 25, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.

  • CVE-2008-0911Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

  • CVE-2008-0912Feb 22, 2008
    risk 0.04cvss —epss 0.16

    Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a…

  • CVE-2008-0913Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an unspecified context.

  • CVE-2008-0914Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-0915Feb 22, 2008
    risk 0.00cvss —epss 0.01

    The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value.

  • CVE-2008-0916Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.

  • CVE-2008-0917Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor…

  • CVE-2008-0918Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the…

  • CVE-2008-0919Feb 22, 2008
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

  • CVE-2008-0920Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular…

  • CVE-2008-0921Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-0922Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.

  • CVE-2008-0910Feb 22, 2008
    risk 0.00cvss —epss 0.03

    Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to…

  • CVE-2008-0162Feb 22, 2008
    risk 0.00cvss —epss 0.00

    misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

  • CVE-2008-0895Feb 22, 2008
    risk 0.00cvss —epss 0.02

    BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.

  • CVE-2008-0896Feb 22, 2008
    risk 0.00cvss —epss 0.01

    BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.

  • CVE-2008-0897Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to…

  • CVE-2008-0898Feb 22, 2008
    risk 0.00cvss —epss 0.01

    The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access…

  • CVE-2008-0899Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

  • CVE-2008-0900Feb 22, 2008
    risk 0.01cvss —epss 0.10

    Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.

  • CVE-2008-0901Feb 22, 2008
    risk 0.00cvss —epss 0.02

    BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

  • CVE-2008-0902Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.

  • CVE-2008-0903Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL.

  • CVE-2008-0904Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.

  • CVE-2008-0905Feb 22, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2008-0906Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.

  • CVE-2008-0907Feb 22, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2008-0908Feb 22, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-0909Feb 22, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to inject arbitrary web script or HTML via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2008-0894Feb 21, 2008
    risk 0.00cvss —epss 0.01

    Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420.

  • CVE-2007-4516Feb 21, 2008
    risk 0.00cvss —epss 0.01

    The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation 5.0 for Windows allows remote attackers to cause a denial of service (daemon crash or hang) via malformed packets.

  • CVE-2008-0638Feb 21, 2008
    risk 0.00cvss —epss 0.06

    Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted value of a certain size field, which is not checked for…

  • CVE-2008-0871Feb 21, 2008
    risk 0.06cvss —epss 0.33

    Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.

  • CVE-2008-0872Feb 21, 2008
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.

  • CVE-2008-0873Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.

  • CVE-2008-0874Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

  • CVE-2008-0875Feb 21, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Hitachi EUR Print Manager, and related Client and Local Server products, 05-06 through 05-06-/B and 05-08 allows remote attackers to cause a denial of service (service hang or termination) via unspecified vectors related to "unexpected data."

  • CVE-2008-0876Feb 21, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via "invalid data."

  • CVE-2008-0877Feb 21, 2008
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme,…

  • CVE-2008-0878Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

  • CVE-2008-0879Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.

  • CVE-2008-0880Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

  • CVE-2008-0881Feb 21, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.

  • CVE-2008-0882Feb 21, 2008
    risk 0.00cvss —epss 0.06

    Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation…

  • CVE-2008-0861Feb 21, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action.

  • CVE-2008-0862Feb 21, 2008
    risk 0.00cvss —epss 0.02

    IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.