VYPR

CVEs

383,654 total · page 7107 of 7,674

  • CVE-2007-6285Dec 20, 2007
    risk 0.00cvss —epss 0.00

    The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and…

  • CVE-2007-6472Dec 20, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days…

  • CVE-2007-6473Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command.

  • CVE-2007-6474Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.

  • CVE-2007-6475Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_sel parameter to (1) updater.php and (2) thumber.php.

  • CVE-2007-6476Dec 20, 2007
    risk 0.03cvss —epss 0.03

    GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.

  • CVE-2007-6477Dec 20, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2007-6478Dec 20, 2007
    risk 0.03cvss —epss 0.06

    Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. NOTE: some of these details are obtained from third…

  • CVE-2007-6479Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be…

  • CVE-2007-6480Dec 20, 2007
    risk 0.00cvss —epss 0.04

    The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.

  • CVE-2007-6481Dec 20, 2007
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to create or delete arbitrary directories via unspecified vectors.

  • CVE-2007-6482Dec 20, 2007
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

  • CVE-2007-6483Dec 20, 2007
    risk 0.04cvss —epss 0.10

    Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.

  • CVE-2007-6484Dec 20, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in phpRPG 0.8 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2007-6485Dec 20, 2007
    risk 0.04cvss —epss 0.11

    Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.

  • CVE-2007-6486Dec 20, 2007
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party…

  • CVE-2007-6487Dec 20, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Plain Black WebGUI 7.4.0 through 7.4.17 allows remote authenticated users with Secondary Admin privileges to create Admin accounts, a different vulnerability than CVE-2006-0680.

  • CVE-2007-6488Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.

  • CVE-2007-6489Dec 20, 2007
    risk 0.04cvss —epss 0.07

    Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.

  • CVE-2007-6490Dec 20, 2007
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.

  • CVE-2007-6491Dec 20, 2007
    risk 0.00cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Kvaliitti WebDoc 3.0 CMS allow remote attackers to execute arbitrary SQL commands via (1) the cat_id parameter to categories.asp; and probably (2) the document_id parameter to categories.asp, and the (3) cat_id and (4) document_id…

  • CVE-2007-6492Dec 20, 2007
    risk 0.00cvss —epss 0.02

    The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via an empty string in the argument to the ProcessRequestEx method.

  • CVE-2007-6493Dec 20, 2007
    risk 0.04cvss —epss 0.07

    The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to execute arbitrary code via a certain argument to the SetHandler method.

  • CVE-2007-6494Dec 20, 2007
    risk 0.04cvss —epss 0.12

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.

  • CVE-2007-6495Dec 20, 2007
    risk 0.03cvss —epss 0.04

    inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser…

  • CVE-2007-6496Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a…

  • CVE-2007-6497Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a…

  • CVE-2007-6498Dec 20, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to…

  • CVE-2007-6499Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "host id (IIS) value."

  • CVE-2007-6500Dec 20, 2007
    risk 0.03cvss —epss 0.04

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp.

  • CVE-2007-6501Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp.

  • CVE-2007-6502Dec 20, 2007
    risk 0.03cvss —epss 0.03

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using…

  • CVE-2007-6503Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to hosting/AutoSignUpPlans.asp…

  • CVE-2007-6504Dec 20, 2007
    risk 0.03cvss —epss 0.02

    Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter.

  • CVE-2007-5584Dec 20, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to cause a denial of service (device reload) via crafted "data in the control-plane path with Layer 7 Application Inspections."

  • CVE-2007-6351Dec 20, 2007
    risk 0.00cvss —epss 0.02

    libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.

  • CVE-2007-6352Dec 20, 2007
    risk 0.00cvss —epss 0.03

    Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.

  • CVE-2007-6430Dec 20, 2007
    risk 0.00cvss —epss 0.02

    Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is…

  • CVE-2007-6242Dec 20, 2007
    risk 0.02cvss —epss 0.30

    Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."

  • CVE-2007-6243Dec 20, 2007
    risk 0.01cvss —epss 0.08

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

  • CVE-2007-6244Dec 20, 2007
    risk 0.04cvss —epss 0.13

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used…

  • CVE-2007-6245Dec 20, 2007
    risk 0.00cvss —epss 0.05

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.

  • CVE-2007-6246Dec 20, 2007
    risk 0.01cvss —epss 0.12

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.

  • CVE-2007-6335Dec 20, 2007
    risk 0.04cvss —epss 0.18

    Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.

  • CVE-2007-6336Dec 20, 2007
    risk 0.00cvss —epss 0.04

    Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.

  • CVE-2007-6353Dec 20, 2007
    risk 0.00cvss —epss 0.05

    Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.

  • CVE-2007-5966Dec 20, 2007
    risk 0.00cvss —epss 0.00

    Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code or cause a denial of service (panic) via a large relative timeout value. NOTE: some of these details are obtained from third…

  • CVE-2007-6281Dec 20, 2007
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in Open File Manager service (ofmnt.exe) in St. Bernard Open File Manager 9.5 allows remote attackers to execute arbitrary code via a long request.

  • CVE-2007-6452Dec 20, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the benchmark reporting system in Google Web Toolkit (GWT) before 1.4.61 has unknown impact and attack vectors, possibly related to cross-site scripting (XSS).

  • CVE-2007-6453Dec 20, 2007
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter.