VYPR

CVEs

382,385 total · page 7181 of 7,648

  • CVE-2007-1403Mar 10, 2007
    risk 0.05cvss —epss 0.29

    Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4)…

  • CVE-2007-1404Mar 10, 2007
    risk 0.08cvss —epss 0.67

    tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.

  • CVE-2007-1405Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2007-1406Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

  • CVE-2007-1407Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in OpenSolution Quick.Cart before 2.1 has unknown impact and attack vectors, related to a "low critical exploit."

  • CVE-2007-1408Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Multiple vulnerabilities in (1) bank.php, (2) landfill.php, (3) outposts.php, (4) tribes.php, (5) house.php, (6) tribearmor.php, (7) tribeastral.php, (8) tribeware.php, and (9) includes/head.php in Bartek Jasicki Vallheru before 1.3 beta have unknown impact and remote attack…

  • CVE-2007-1409Mar 10, 2007
    risk 0.00cvss —epss 0.02

    WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

  • CVE-2007-1410Mar 10, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.

  • CVE-2007-1411Mar 10, 2007
    risk 0.04cvss —epss 0.07

    Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

  • CVE-2007-1365Mar 10, 2007
    risk 0.04cvss —epss 0.18

    Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service.

  • CVE-2007-1273Mar 10, 2007
    risk 0.00cvss —epss 0.00

    Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain…

  • CVE-2007-0999Mar 10, 2007
    risk 0.00cvss —epss 0.03

    Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.

  • CVE-2007-1345Mar 10, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in cube.exe in the GINA component for CA (Computer Associates) eTrust Admin 8.1.0 through 8.1.2 allows attackers with physical interactive or Remote Desktop access to bypass authentication and gain privileges via the password reset interface.

  • CVE-2007-1388Mar 10, 2007
    risk 0.03cvss —epss 0.01

    The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid…

  • CVE-2007-1384Mar 10, 2007
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.2 allows remote attackers to overwrite arbitrary files via ".." sequences in a torrent filename.

  • CVE-2007-1385Mar 10, 2007
    risk 0.00cvss —epss 0.02

    chunkcounter.cpp in KTorrent before 2.1.2 allows remote attackers to cause a denial of service (crash) and heap corruption via a negative or large idx value.

  • CVE-2006-7163Mar 10, 2007
    risk 0.00cvss —epss 0.00

    DreameeSoft Password Master 1.0 stores the database in an unencrypted format when the master password is set, which allows attackers with physical access to read the database contents via an unspecified authentication bypass. NOTE: the provenance of this information is unknown;…

  • CVE-2007-0005Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.

  • CVE-2007-1371Mar 10, 2007
    risk 0.03cvss —epss 0.04

    Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by…

  • CVE-2007-1372Mar 10, 2007
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.

  • CVE-2007-1373Mar 10, 2007
    risk 0.08cvss —epss 0.59

    Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the same issue as CVE-2006-5961.

  • CVE-2007-1374Mar 10, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2007-1375Mar 10, 2007
    risk 0.04cvss —epss 0.08

    Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.

  • CVE-2007-1376Mar 10, 2007
    risk 0.04cvss —epss 0.10

    The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate…

  • CVE-2007-1377Mar 10, 2007
    risk 0.04cvss —epss 0.17

    AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a…

  • CVE-2007-1378Mar 10, 2007
    risk 0.00cvss —epss 0.01

    The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.

  • CVE-2007-1379Mar 10, 2007
    risk 0.00cvss —epss 0.02

    The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.

  • CVE-2007-1380Mar 10, 2007
    risk 0.04cvss —epss 0.09

    The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer…

  • CVE-2007-1381Mar 10, 2007
    risk 0.04cvss —epss 0.09

    The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code…

  • CVE-2007-1382Mar 10, 2007
    risk 0.03cvss —epss 0.02

    The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.

  • CVE-2007-1383CriMar 10, 2007
    risk 0.68cvss 9.8epss 0.15

    Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.

  • CVE-2007-1367Mar 9, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.

  • CVE-2007-1368Mar 9, 2007
    risk 0.00cvss —epss 0.01

    The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.

  • CVE-2007-1369Mar 9, 2007
    risk 0.03cvss —epss 0.01

    ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini…

  • CVE-2007-1370Mar 9, 2007
    risk 0.00cvss —epss 0.00

    Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other…

  • CVE-2007-1338Mar 8, 2007
    risk 0.00cvss —epss 0.03

    The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connections" setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would…

  • CVE-2007-1339Mar 8, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter.

  • CVE-2007-1340Mar 8, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter.

  • CVE-2007-1341Mar 8, 2007
    risk 0.00cvss —epss 0.01

    include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.

  • CVE-2007-1342Mar 8, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.

  • CVE-2007-1343Mar 8, 2007
    risk 0.00cvss —epss 0.02

    includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant…

  • CVE-2007-1344Mar 8, 2007
    risk 0.00cvss —epss 0.06

    Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes…

  • CVE-2007-1346Mar 8, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset or turn off the server.

  • CVE-2007-1347Mar 8, 2007
    risk 0.05cvss —epss 0.30

    Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in…

  • CVE-2007-1350Mar 8, 2007
    risk 0.02cvss —epss 0.19

    Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.

  • CVE-2007-1359Mar 8, 2007
    risk 0.04cvss —epss 0.07

    Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still…

  • CVE-2007-1360Mar 8, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL parameters.

  • CVE-2007-1361Mar 8, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue is probably different than CVE-2007-0376.

  • CVE-2006-7162Mar 7, 2007
    risk 0.00cvss —epss 0.00

    PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files.

  • CVE-2007-1324Mar 7, 2007
    risk 0.00cvss —epss 0.02

    SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.