VYPR

CVEs

381,246 total · page 7147 of 7,625

  • CVE-2007-1946Apr 11, 2007
    risk 0.02cvss —epss 0.26

    Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.

  • CVE-2007-1947Apr 11, 2007
    risk 0.03cvss —epss 0.04

    Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the…

  • CVE-2007-1948Apr 11, 2007
    risk 0.04cvss —epss 0.08

    Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and…

  • CVE-2007-1949Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

  • CVE-2007-1950Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.

  • CVE-2007-1951Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

  • CVE-2007-1952Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

  • CVE-2007-1953Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

  • CVE-2007-1954Apr 11, 2007
    risk 0.00cvss —epss 0.02

    Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.

  • CVE-2007-1955Apr 11, 2007
    risk 0.00cvss —epss 0.05

    Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions, a…

  • CVE-2007-1956Apr 11, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.

  • CVE-2007-1957Apr 11, 2007
    risk 0.00cvss —epss 0.01

    Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/.

  • CVE-2007-1357Apr 11, 2007
    risk 0.00cvss —epss 0.14

    The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made…

  • CVE-2007-1904Apr 10, 2007
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.

  • CVE-2007-1905Apr 10, 2007
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".

  • CVE-2007-1906Apr 10, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.

  • CVE-2007-1907Apr 10, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

  • CVE-2007-1908Apr 10, 2007
    risk 0.03cvss —epss 0.03

    PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.

  • CVE-2007-1909Apr 10, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.

  • CVE-2007-1910Apr 10, 2007
    risk 0.05cvss —epss 0.25

    Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.

  • CVE-2007-1911Apr 10, 2007
    risk 0.04cvss —epss 0.12

    Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.

  • CVE-2007-1912Apr 10, 2007
    risk 0.04cvss —epss 0.11

    Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.

  • CVE-2007-1913Apr 10, 2007
    risk 0.00cvss —epss 0.02

    The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is…

  • CVE-2007-1914Apr 10, 2007
    risk 0.00cvss —epss 0.02

    The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is…

  • CVE-2007-1915Apr 10, 2007
    risk 0.00cvss —epss 0.04

    Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the…

  • CVE-2007-1916Apr 10, 2007
    risk 0.01cvss —epss 0.07

    Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace…

  • CVE-2007-1917Apr 10, 2007
    risk 0.01cvss —epss 0.07

    Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after…

  • CVE-2007-1918Apr 10, 2007
    risk 0.00cvss —epss 0.03

    The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information…

  • CVE-2007-1919Apr 10, 2007
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2007-1920Apr 10, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.

  • CVE-2007-1921Apr 10, 2007
    risk 0.00cvss —epss 0.05

    LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT file that contains a value that is used as an offset, which triggers memory corruption.

  • CVE-2007-1922Apr 10, 2007
    risk 0.00cvss —epss 0.05

    The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory…

  • CVE-2007-1923Apr 10, 2007
    risk 0.00cvss —epss 0.03

    (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.

  • CVE-2007-1924Apr 10, 2007
    risk 0.00cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php. NOTE: this issue is disputed by CVE and a reliable third party,…

  • CVE-2007-1925Apr 10, 2007
    risk 0.00cvss —epss 0.01

    The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticated users to delete arbitrary accounts via a modified cookie.

  • CVE-2007-1926Apr 10, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log;…

  • CVE-2007-1927Apr 10, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.

  • CVE-2007-1928Apr 10, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.

  • CVE-2007-1929Apr 10, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter.

  • CVE-2007-1930Apr 10, 2007
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.

  • CVE-2007-1931Apr 10, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

  • CVE-2007-1932Apr 10, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.

  • CVE-2007-1933Apr 10, 2007
    risk 0.04cvss —epss 0.06

    Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.

  • CVE-2007-1934Apr 10, 2007
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.

  • CVE-2007-1935Apr 10, 2007
    risk 0.00cvss —epss 0.01

    PHP file inclusion vulnerability in admin/index.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the site parameter, which is accessed by the file_exists function.

  • CVE-2007-1936Apr 10, 2007
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in scaradcontrol.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sac_config_dir parameter.

  • CVE-2007-1937Apr 10, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.

  • CVE-2007-1938Apr 10, 2007
    risk 0.00cvss —epss 0.01

    Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).

  • CVE-2007-1939Apr 10, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

  • CVE-2006-7192Apr 10, 2007
    risk 0.02cvss —epss 0.23

    Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE…