VYPR

CVEs

382,325 total · page 7189 of 7,647

  • CVE-2007-1049Feb 21, 2007
    risk 0.00cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to…

  • CVE-2007-1010Feb 21, 2007
    risk 0.04cvss —epss 0.07

    Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

  • CVE-2007-1011Feb 21, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.

  • CVE-2007-1012Feb 21, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.

  • CVE-2007-1013Feb 21, 2007
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.

  • CVE-2007-1014Feb 21, 2007
    risk 0.04cvss —epss 0.09

    Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.

  • CVE-2007-1015Feb 21, 2007
    risk 0.03cvss —epss 0.03

    SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-1016Feb 21, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters. NOTE: the provenance of this information is unknown; the…

  • CVE-2007-1017Feb 21, 2007
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.

  • CVE-2007-1018Feb 21, 2007
    risk 0.00cvss —epss 0.02

    PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter. NOTE: the provenance of this information…

  • CVE-2007-1019Feb 21, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.

  • CVE-2007-1020Feb 21, 2007
    risk 0.03cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.

  • CVE-2007-1021Feb 21, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.

  • CVE-2007-1022Feb 21, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2007-1023Feb 21, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-1024Feb 21, 2007
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.

  • CVE-2007-1025Feb 21, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.

  • CVE-2007-1026Feb 21, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are obtained from third party information.

  • CVE-2007-1027Feb 21, 2007
    risk 0.00cvss —epss 0.00

    Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.

  • CVE-2007-1028Feb 21, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTML entities and the IMG element.

  • CVE-2007-1029Feb 21, 2007
    risk 0.04cvss —epss 0.07

    Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.

  • CVE-2007-1030Feb 21, 2007
    risk 0.00cvss —epss 0.03

    Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.

  • CVE-2007-1031Feb 21, 2007
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.

  • CVE-2007-1032Feb 21, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

  • CVE-2007-1033Feb 21, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.

  • CVE-2007-1034Feb 21, 2007
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2007-1035Feb 21, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.

  • CVE-2007-1036Feb 21, 2007
    risk 0.10cvss —epss 0.82

    The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.

  • CVE-2007-1070Feb 21, 2007
    risk 0.09cvss —epss 0.73

    Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1)…

  • CVE-2007-0325Feb 20, 2007
    risk 0.06cvss —epss 0.35

    Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow…

  • CVE-2007-0772Feb 20, 2007
    risk 0.00cvss —epss 0.04

    The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.

  • CVE-2007-0988Feb 20, 2007
    risk 0.00cvss —epss 0.02

    The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used…

  • CVE-2007-1007Feb 20, 2007
    risk 0.01cvss —epss 0.07

    Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.

  • CVE-2007-0007Feb 20, 2007
    risk 0.00cvss —epss 0.00

    gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.

  • CVE-2007-1004Feb 20, 2007
    risk 0.00cvss —epss 0.01

    Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

  • CVE-2006-5276Feb 20, 2007
    risk 0.09cvss —epss 0.79

    Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

  • CVE-2007-1006Feb 20, 2007
    risk 0.00cvss —epss 0.04

    Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.

  • CVE-2007-1008Feb 20, 2007
    risk 0.03cvss —epss 0.02

    Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to…

  • CVE-2007-0451Feb 16, 2007
    risk 0.01cvss —epss 0.07

    Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

  • CVE-2007-0710Feb 16, 2007
    risk 0.03cvss —epss 0.03

    The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.

  • CVE-2007-0897HigFeb 16, 2007
    risk 0.49cvss 7.5epss 0.04

    Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a…

  • CVE-2007-0898Feb 16, 2007
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.

  • CVE-2007-0982Feb 16, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2007-0983Feb 16, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.

  • CVE-2007-0984Feb 16, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.

  • CVE-2007-0985Feb 16, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.

  • CVE-2007-0986Feb 16, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.

  • CVE-2007-0987Feb 16, 2007
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname, in the n parameter.

  • CVE-2007-0969Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

  • CVE-2007-0970Feb 16, 2007
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.