VYPR

CVEs

381,690 total · page 7146 of 7,634

  • CVE-2007-1744May 2, 2007
    risk 0.00cvss —epss 0.00

    Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.

  • CVE-2007-1876May 2, 2007
    risk 0.00cvss —epss 0.00

    VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."

  • CVE-2007-1877May 2, 2007
    risk 0.00cvss —epss 0.02

    VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.

  • CVE-2007-0655May 2, 2007
    risk 0.00cvss —epss 0.03

    The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.

  • CVE-2007-2457May 2, 2007
    risk 0.04cvss —epss 0.12

    PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.

  • CVE-2007-2458May 2, 2007
    risk 0.04cvss —epss 0.10

    Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than…

  • CVE-2007-2459May 2, 2007
    risk 0.00cvss —epss 0.05

    Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files.

  • CVE-2007-2460May 2, 2007
    risk 0.00cvss —epss 0.02

    PHP remote file inclusion vulnerability in modules/admin/include/config.php in FireFly 1.1.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2007-1320May 2, 2007
    risk 0.00cvss —epss 0.00

    Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark…

  • CVE-2007-1322May 2, 2007
    risk 0.00cvss —epss 0.00

    QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.

  • CVE-2007-1366May 2, 2007
    risk 0.00cvss —epss 0.00

    QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.

  • CVE-2007-2454May 2, 2007
    risk 0.00cvss —epss 0.00

    Heap-based buffer overflow in the VGA device in Parallels allows local users, with root access to the guest operating system, to terminate the virtual machine and possibly execute arbitrary code in the host operating system via unspecified vectors related to bitblt operations.

  • CVE-2007-2455May 2, 2007
    risk 0.00cvss —epss 0.01

    Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by…

  • CVE-2007-2456May 2, 2007
    risk 0.04cvss —epss 0.09

    Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.

  • CVE-2007-2241May 2, 2007
    risk 0.01cvss —epss 0.08

    Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.

  • CVE-2007-2432May 2, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in utilities/search.asp in nukedit 4.9.7b allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2007-2433May 2, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Ariadne 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the ARLogin parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2007-2434May 2, 2007
    risk 0.04cvss —epss 0.14

    Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed DNS query.

  • CVE-2007-2435May 2, 2007
    risk 0.00cvss —epss 0.05

    Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and…

  • CVE-2007-2437May 2, 2007
    risk 0.03cvss —epss 0.04

    The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions,…

  • CVE-2007-2420May 2, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-2421May 2, 2007
    risk 0.00cvss —epss 0.04

    Buffer overflow in Hitachi Groupmax Mobile Option for Mobile-Phone 07-00 through 07-30, 5 for i-mode 05-11 through 05-23, and 6 for EZweb 06-00 through 06-04 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2007-2422CriMay 2, 2007
    risk 0.64cvss 9.8epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability…

  • CVE-2007-2423May 2, 2007
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the do parameter in an AttachFile action, a different vulnerability than CVE-2007-0857. NOTE: the provenance of this information is…

  • CVE-2007-2424May 2, 2007
    risk 0.04cvss —epss 0.10

    PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the show parameter.

  • CVE-2007-2425May 2, 2007
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter.

  • CVE-2007-2426May 2, 2007
    risk 0.08cvss —epss 0.63

    PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter.

  • CVE-2007-2427May 2, 2007
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2007-2428May 2, 2007
    risk 0.04cvss —epss 0.09

    Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) fp or (2) sc parameter.

  • CVE-2007-2429May 2, 2007
    risk 0.04cvss —epss 0.08

    ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is…

  • CVE-2007-2430May 2, 2007
    risk 0.03cvss —epss 0.04

    shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by placing file contents and directory traversal manipulations into a SessionUserLang cookie to public/code/index.php.

  • CVE-2007-2431May 2, 2007
    risk 0.03cvss —epss 0.05

    Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks by modifying critical variables such as $_SERVER, as demonstrated by injecting web…

  • CVE-2007-2411May 1, 2007
    risk 0.00cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. NOTE: a third party disputes this vulnerability, stating that "the application is not vulnerable to this issue.

  • CVE-2007-2412May 1, 2007
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter. NOTE: a third party has disputed this issue because the a array is populated by a database query before…

  • CVE-2007-2414May 1, 2007
    risk 0.00cvss —epss 0.03

    MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2007-2415May 1, 2007
    risk 0.00cvss —epss 0.02

    Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a "clean" exit in which "the server I/O loop finishes and the…

  • CVE-2007-2416May 1, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a parameter.

  • CVE-2006-7199Apr 30, 2007
    risk 0.00cvss —epss 0.02

    EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server. NOTE: the vendor disputes the severity of the issue,…

  • CVE-2006-7200Apr 30, 2007
    risk 0.00cvss —epss 0.01

    EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier for attackers to bypass one stage of authentication by stealing and replaying a token.

  • CVE-2006-7201Apr 30, 2007
    risk 0.00cvss —epss 0.02

    EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared object), which might allow remote attackers to obtain the token via HTTP.

  • CVE-2007-2367Apr 30, 2007
    risk 0.03cvss —epss 0.04

    Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.

  • CVE-2007-2368Apr 30, 2007
    risk 0.03cvss —epss 0.02

    picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.

  • CVE-2007-2369Apr 30, 2007
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

  • CVE-2007-2370Apr 30, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.

  • CVE-2007-2371Apr 30, 2007
    risk 0.04cvss —epss 0.08

    admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via…

  • CVE-2007-2372Apr 30, 2007
    risk 0.04cvss —epss 0.08

    admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and…

  • CVE-2007-2373Apr 30, 2007
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2007-2374Apr 30, 2007
    risk 0.01cvss —epss 0.17

    Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is…

  • CVE-2007-2375Apr 30, 2007
    risk 0.00cvss —epss 0.05

    The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.

  • CVE-2007-2376Apr 30, 2007
    risk 0.00cvss —epss 0.02

    The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data…