VYPR

CVEs

383,732 total · page 7100 of 7,675

  • CVE-2008-0361Jan 18, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.

  • CVE-2008-0362Jan 18, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.

  • CVE-2008-0363Jan 18, 2008
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.

  • CVE-2008-0350Jan 18, 2008
    risk 0.03cvss —epss 0.03

    admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.

  • CVE-2008-0351Jan 18, 2008
    risk 0.03cvss —epss 0.02

    admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.

  • CVE-2008-0352Jan 18, 2008
    risk 0.04cvss —epss 0.10

    The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).

  • CVE-2008-0171Jan 17, 2008
    risk 0.00cvss —epss 0.03

    regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.

  • CVE-2008-0172Jan 17, 2008
    risk 0.00cvss —epss 0.02

    The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.

  • CVE-2008-0339Jan 17, 2008
    risk 0.04cvss —epss 0.15

    Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.

  • CVE-2008-0340Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).

  • CVE-2008-0341Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.

  • CVE-2008-0342Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.

  • CVE-2008-0343Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.

  • CVE-2008-0344Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.

  • CVE-2008-0345Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.

  • CVE-2008-0346Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.

  • CVE-2008-0347Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a…

  • CVE-2008-0348Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.

  • CVE-2008-0349Jan 17, 2008
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.

  • CVE-2008-0325Jan 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-0326Jan 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

  • CVE-2008-0327Jan 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-0328Jan 17, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-0329Jan 17, 2008
    risk 0.03cvss —epss 0.02

    LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter.

  • CVE-2008-0330Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.

  • CVE-2008-0331Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.

  • CVE-2008-0332Jan 17, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

  • CVE-2008-0333Jan 17, 2008
    risk 0.04cvss —epss 0.12

    Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.

  • CVE-2008-0334Jan 17, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.

  • CVE-2008-0335Jan 17, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.

  • CVE-2008-0336Jan 17, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx,…

  • CVE-2008-0337Jan 17, 2008
    risk 0.03cvss —epss 0.05

    Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.

  • CVE-2008-0338Jan 17, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.

  • CVE-2008-0027Jan 17, 2008
    risk 0.05cvss —epss 0.57

    Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a…

  • CVE-2008-0324Jan 17, 2008
    risk 0.03cvss —epss 0.01

    Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.

  • CVE-2007-6685Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.

  • CVE-2007-6686Jan 17, 2008
    risk 0.00cvss —epss 0.02

    The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.

  • CVE-2007-6687Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP PROPPATCH in the WebDAV module.

  • CVE-2007-6688Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the storage folder."

  • CVE-2007-6689Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.

  • CVE-2007-6690Jan 17, 2008
    risk 0.00cvss —epss 0.02

    The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.

  • CVE-2007-6691Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the WebDAV module, (3) a comment view in the Comment module, (4) unspecified "item information disclosure…

  • CVE-2007-6692Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.

  • CVE-2007-6693Jan 17, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."

  • CVE-2008-0302Jan 17, 2008
    risk 0.00cvss —epss 0.01

    Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.

  • CVE-2007-6681Jan 17, 2008
    risk 0.04cvss —epss 0.17

    Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.

  • CVE-2007-6682Jan 17, 2008
    risk 0.04cvss —epss 0.15

    Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.

  • CVE-2007-6683Jan 17, 2008
    risk 0.00cvss —epss 0.03

    The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

  • CVE-2007-6684Jan 17, 2008
    risk 0.00cvss —epss 0.02

    The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dereference.

  • CVE-2008-0081CriJan 16, 2008
    risk 0.71cvss 9.8epss 0.58

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.