VYPR

CVEs

383,488 total · page 7112 of 7,670

  • CVE-2007-6119Nov 23, 2007
    risk 0.00cvss —epss 0.03

    The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.

  • CVE-2007-6120Nov 23, 2007
    risk 0.00cvss —epss 0.02

    The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

  • CVE-2007-6121Nov 23, 2007
    risk 0.00cvss —epss 0.02

    Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.

  • CVE-2007-6082Nov 22, 2007
    risk 0.03cvss —epss 0.04

    Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.

  • CVE-2007-6083Nov 22, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

  • CVE-2007-6084Nov 22, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-6085Nov 22, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module.

  • CVE-2007-6086Nov 22, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the module parameter.

  • CVE-2007-6087Nov 22, 2007
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parameters to the changepass module.

  • CVE-2007-6088Nov 22, 2007
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

  • CVE-2007-6089Nov 22, 2007
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

  • CVE-2007-6090Nov 22, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2007-6091Nov 22, 2007
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password…

  • CVE-2007-6092Nov 22, 2007
    risk 0.00cvss —epss 0.02

    Buffer overflow in libsrtp in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

  • CVE-2007-6093Nov 22, 2007
    risk 0.00cvss —epss 0.01

    The SRTP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (kernel crash) via an RTCP index that is "much more than expected."

  • CVE-2007-6094Nov 22, 2007
    risk 0.00cvss —epss 0.01

    The IPsec module in the VPN component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (module crash) via an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS).

  • CVE-2007-6095Nov 22, 2007
    risk 0.00cvss —epss 0.01

    The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to receive messages intended for other users.

  • CVE-2007-6096Nov 22, 2007
    risk 0.00cvss —epss 0.01

    Ingate Firewall before 4.6.0 and SIParator before 4.6.0 use cleartext storage for passwords of "administrators with less privileges," which might allow attackers to read these passwords via unknown vectors.

  • CVE-2007-6097Nov 22, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the ICMP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and remote attack vectors, related to ICMP packets that are "incorrectly accepted."

  • CVE-2007-6098Nov 22, 2007
    risk 0.00cvss —epss 0.01

    Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for…

  • CVE-2007-6099Nov 22, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 might leave "media pinholes" open upon a restart of the SIP module, which might make it easier for remote attackers to conduct unauthorized activities.

  • CVE-2007-6081Nov 21, 2007
    risk 0.00cvss —epss 0.01

    AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000.

  • CVE-2007-5612Nov 21, 2007
    risk 0.00cvss —epss 0.02

    CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large number of idle connections.

  • CVE-2007-6078Nov 21, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.asp, possibly involving a parameter passed from cp_main.asp; (3) inc_profile_functions.asp; or (4)…

  • CVE-2007-6079Nov 21, 2007
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using…

  • CVE-2007-6080Nov 21, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

  • CVE-2007-6077Nov 21, 2007
    risk 0.00cvss —epss 0.03

    The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest,…

  • CVE-2007-6063Nov 21, 2007
    risk 0.00cvss —epss 0.00

    Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.

  • CVE-2007-6061Nov 20, 2007
    risk 0.00cvss —epss 0.03

    Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be…

  • CVE-2007-6062Nov 20, 2007
    risk 0.00cvss —epss 0.02

    irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.

  • CVE-2007-6044Nov 20, 2007
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known…

  • CVE-2007-6045Nov 20, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.

  • CVE-2007-6046Nov 20, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.

  • CVE-2007-6047Nov 20, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.

  • CVE-2007-6048Nov 20, 2007
    risk 0.00cvss —epss 0.02

    IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

  • CVE-2007-6049Nov 20, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.

  • CVE-2007-6050Nov 20, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."

  • CVE-2007-6051Nov 20, 2007
    risk 0.00cvss —epss 0.02

    IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

  • CVE-2007-6052Nov 20, 2007
    risk 0.00cvss —epss 0.01

    IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it…

  • CVE-2007-6053Nov 20, 2007
    risk 0.00cvss —epss 0.01

    IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is…

  • CVE-2007-6054Nov 20, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI,…

  • CVE-2007-6055Nov 20, 2007
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified…

  • CVE-2007-6056Nov 20, 2007
    risk 0.03cvss —epss 0.03

    frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task details via modified values to the (1) Mehr and (2) SUPER parameters.

  • CVE-2007-6057Nov 20, 2007
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.

  • CVE-2007-6058Nov 20, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in…

  • CVE-2007-6059Nov 20, 2007
    risk 0.00cvss —epss 0.02

    Javamail does not properly handle a series of invalid login attempts in which the same e-mail address is entered as username and password, and the domain portion of this address yields a Java UnknownHostException error, which allows remote attackers to cause a denial of service…

  • CVE-2007-6060Nov 20, 2007
    risk 0.00cvss —epss 0.06

    AhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP header, which allows remote attackers to cause a denial of service (machine crash) and possibly execute arbitrary code via a ZIP…

  • CVE-2007-5361Nov 20, 2007
    risk 0.00cvss —epss 0.02

    The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a…

  • CVE-2007-5899Nov 20, 2007
    risk 0.00cvss —epss 0.03

    The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten…

  • CVE-2007-6039Nov 20, 2007
    risk 0.03cvss —epss 0.01

    PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4)…