VYPR

CVEs

382,384 total · page 7182 of 7,648

  • CVE-2007-1326Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter.

  • CVE-2007-1327Mar 7, 2007
    risk 0.04cvss —epss 0.10

    The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.

  • CVE-2007-1328Mar 7, 2007
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.

  • CVE-2007-1329Mar 7, 2007
    risk 0.00cvss —epss 0.05

    Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting…

  • CVE-2007-1330Mar 7, 2007
    risk 0.03cvss —epss 0.01

    Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting…

  • CVE-2007-1331Mar 7, 2007
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search…

  • CVE-2007-1332Mar 7, 2007
    risk 0.00cvss —epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.

  • CVE-2006-7138Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the…

  • CVE-2006-7139Mar 7, 2007
    risk 0.03cvss —epss 0.03

    Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

  • CVE-2006-7140Mar 7, 2007
    risk 0.00cvss —epss 0.01

    The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents…

  • CVE-2006-7141Mar 7, 2007
    risk 0.03cvss —epss 0.06

    Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such…

  • CVE-2006-7142HigMar 7, 2007
    risk 0.51cvss 7.8epss 0.00

    The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive.

  • CVE-2006-7143Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Call Center Software 0.93 and earlier allows remote attackers to inject arbitrary web script or HTML via the problem description field.

  • CVE-2006-7144Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Call Center Software 0.93 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the user name in the login page.

  • CVE-2006-7145Mar 7, 2007
    risk 0.00cvss —epss 0.01

    edit_user.php in Call Center Software 0.93 and earlier allows remote attackers to obtain sensitive information such as account passwords via a modified user_id parameter.

  • CVE-2006-7146Mar 7, 2007
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this…

  • CVE-2006-7147Mar 7, 2007
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

  • CVE-2006-7148Mar 7, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. NOTE: this might be the same issues as CVE-2006-4893.

  • CVE-2006-7149Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b)…

  • CVE-2006-7150Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.

  • CVE-2006-7151Mar 7, 2007
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary code via a malicious library in the (1) hwcap, (2) 0, and (3) nosegneg subdirectories.

  • CVE-2006-7152Mar 7, 2007
    risk 0.03cvss —epss 0.03

    default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.

  • CVE-2006-7153Mar 7, 2007
    risk 0.00cvss —epss 0.04

    PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.

  • CVE-2006-7154Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Iono allows remote attackers to obtain the full server path via certain requests to (1) templates/iono/admin/denied.tpl.php, (2) templates/iono/admin/index.tpl.php, and (a) other unspecified files in templates/.

  • CVE-2006-7155Mar 7, 2007
    risk 0.00cvss —epss 0.02

    Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attackers to conduct denial of service and replay attacks. NOTE: this issue might be related to CVE-2006-5286.

  • CVE-2006-7156Mar 7, 2007
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

  • CVE-2006-7157Mar 7, 2007
    risk 0.04cvss —epss 0.07

    Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

  • CVE-2006-7158Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it is likely that this issue overlaps one of the identifiers…

  • CVE-2006-7159Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.

  • CVE-2006-7160Mar 7, 2007
    risk 0.00cvss —epss 0.00

    The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey,…

  • CVE-2006-7161Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in giris_yap.asp in Hazir Site 2.0 allows remote attackers to bypass authentication via the (1) k_a class or (2) sifre parameter.

  • CVE-2006-7135Mar 7, 2007
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this…

  • CVE-2006-7136Mar 7, 2007
    risk 0.04cvss —epss 0.09

    Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and…

  • CVE-2006-7137Mar 7, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in TinyPortal before 0.8.6 allows remote attackers to inject arbitrary web script or HTML via the shoutbox.

  • CVE-2007-1288Mar 7, 2007
    risk 0.00cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php, (2) themes.php, (3) directory.php, and (4) sendmsg.php in admin/.

  • CVE-2007-1289Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.

  • CVE-2007-1290Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in ViewReport.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the bug parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2007-1291Mar 7, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.

  • CVE-2007-1292Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in…

  • CVE-2007-1293Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php.

  • CVE-2007-1294Mar 7, 2007
    risk 0.03cvss —epss 0.03

    A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.

  • CVE-2007-1295Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.

  • CVE-2007-1296Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.

  • CVE-2007-1297Mar 7, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

  • CVE-2007-1298Mar 7, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

  • CVE-2007-1299Mar 7, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.

  • CVE-2007-1300Mar 7, 2007
    risk 0.00cvss —epss 0.01

    DOURAN Software Technologies ISPUtil 3.32.84.1, and possibly earlier versions, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and reseller data via a direct request for scripts/activesessions.ini. …

  • CVE-2007-1301Mar 7, 2007
    risk 0.04cvss —epss 0.12

    Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command. NOTE: this is probably different than CVE-2006-6423.

  • CVE-2007-1302Mar 7, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.

  • CVE-2007-1303Mar 7, 2007
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.