VYPR

CVEs

382,304 total · page 7190 of 7,647

  • CVE-2007-0968Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.

  • CVE-2007-0324Feb 15, 2007
    risk 0.01cvss —epss 0.07

    Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2007-0651Feb 15, 2007
    risk 0.00cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in…

  • CVE-2007-0652Feb 15, 2007
    risk 0.00cvss —epss 0.02

    Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.

  • CVE-2007-0958Feb 15, 2007
    risk 0.00cvss —epss 0.00

    Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.

  • CVE-2006-7011Feb 15, 2007
    risk 0.00cvss —epss 0.02

    PHP remote file inclusion vulnerability in adminips.php in Develooping Flash Chat allows remote attackers to execute arbitrary PHP code via a URL in the banned_file parameter. NOTE: CVE disputes this vulnerability because banned_file is set to a constant value

  • CVE-2006-7012Feb 15, 2007
    risk 0.03cvss —epss 0.05

    scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter of a show_text action.

  • CVE-2006-7013Feb 15, 2007
    risk 0.00cvss —epss 0.01

    QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the…

  • CVE-2006-7014Feb 15, 2007
    risk 0.00cvss —epss 0.02

    admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

  • CVE-2006-7015Feb 15, 2007
    risk 0.00cvss —epss 0.04

    PHP remote file inclusion vulnerability in admin.jobline.php in Jobline 1.1.1 allows remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter. NOTE: CVE disputes this issue because the script is protected against direct requests

  • CVE-2006-7016Feb 15, 2007
    risk 0.00cvss —epss 0.02

    phpjobboard allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin.php with adminop=job-edit.

  • CVE-2006-7017Feb 15, 2007
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scripts (1) app_change_email.php, (2) app_change_pwd.php, (3) app_mod_rewrite.php, (4)…

  • CVE-2006-7018Feb 15, 2007
    risk 0.00cvss —epss 0.04

    phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via a crafted argument to the nome_evento parameter to phpwcms_code_snippets/mail_file_form.php and (2) sample_ext_php/mail_file_form.php, which is processed by the…

  • CVE-2006-7019Feb 15, 2007
    risk 0.00cvss —epss 0.02

    phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to execute arbitrary code via crafted arguments to the (1) text_evento and (2) email_eventonome_evento parameters to phpwcms_code_snippets/mail_file_form.php and sample_ext_php/mail_file_form.php, which…

  • CVE-2006-7020Feb 15, 2007
    risk 0.00cvss —epss 0.01

    CRLF injection vulnerability in (1) include/inc_act/act_formmailer.php and possibly (2) sample_ext_php/mail_file_form.php in phpwcms 1.2.5-DEV and earlier, and 1.1 before RC4, allows remote attackers to modify HTTP headers and send spam e-mail via a spoofed HTTP Referer…

  • CVE-2006-7021Feb 15, 2007
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.

  • CVE-2006-7022Feb 15, 2007
    risk 0.00cvss —epss 0.02

    The Tools module in fx-APP 0.0.8.1 allows remote attackers to misrepresent the contents of a web page via an arbitrary URL in the url parameter to a showhtml action for index.php, which causes the URL to be displayed within an iframe.

  • CVE-2006-7023Feb 15, 2007
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1 allow remote attackers to inject arbitrary HTML or web script via (1) the search box, and the (2) url, (3) website, (4) comment, and (5) signature fields in the profile, and possibly (6) a menu item.

  • CVE-2006-7024Feb 15, 2007
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Harpia CMS 1.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) func_prog parameter to (a) preload.php and (b) index.php; (2) header_prog parameter to (c) missing.php and (d) email.php,…

  • CVE-2007-0949Feb 15, 2007
    risk 0.04cvss —epss 0.16

    Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected.

  • CVE-2007-0950Feb 15, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

  • CVE-2007-0951Feb 15, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2007-0952Feb 15, 2007
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range.

  • CVE-2007-0953Feb 15, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

  • CVE-2007-0954Feb 15, 2007
    risk 0.00cvss —epss 0.02

    MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors.

  • CVE-2007-0955Feb 15, 2007
    risk 0.03cvss —epss 0.06

    The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in…

  • CVE-2007-0919Feb 14, 2007
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.

  • CVE-2007-0920Feb 14, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

  • CVE-2007-0921Feb 14, 2007
    risk 0.00cvss —epss 0.02

    Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.

  • CVE-2007-0922Feb 14, 2007
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in Portal Search allows remote attackers to inject arbitrary web script or HTML via the query string.

  • CVE-2007-0923Feb 14, 2007
    risk 0.00cvss —epss 0.02

    buscador/buscador.htm in Portal Search allows remote attackers to obtain sensitive information (business logic) via a query string composed of a search for certain characters.

  • CVE-2007-0924Feb 14, 2007
    risk 0.00cvss —epss 0.02

    Till Gerken phpPolls 1.0.3 allows remote attackers to bypass authentication and perform certain administrative actions via a direct request to phpPollAdmin.php3. NOTE: this issue might subsume CVE-2006-3764.

  • CVE-2007-0925Feb 14, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2007-0926Feb 14, 2007
    risk 0.00cvss —epss 0.01

    The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.

  • CVE-2007-0927Feb 14, 2007
    risk 0.07cvss —epss 0.45

    Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.

  • CVE-2007-0928Feb 14, 2007
    risk 0.00cvss —epss 0.01

    Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt.

  • CVE-2007-0929Feb 14, 2007
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in php rrd browser before 0.2.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter.

  • CVE-2007-0930Feb 14, 2007
    risk 0.00cvss —epss 0.01

    Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.

  • CVE-2007-0931Feb 14, 2007
    risk 0.00cvss —epss 0.06

    Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code…

  • CVE-2007-0932Feb 14, 2007
    risk 0.00cvss —epss 0.02

    The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the…

  • CVE-2006-5860Feb 14, 2007
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2007-0914Feb 14, 2007
    risk 0.00cvss —epss 0.02

    Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.

  • CVE-2007-0915Feb 14, 2007
    risk 0.00cvss —epss 0.04

    Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.

  • CVE-2007-0916Feb 14, 2007
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

  • CVE-2007-0917Feb 14, 2007
    risk 0.00cvss —epss 0.02

    The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.

  • CVE-2007-0918Feb 14, 2007
    risk 0.00cvss —epss 0.03

    The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by…

  • CVE-2006-5859Feb 14, 2007
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.

  • CVE-2007-0913Feb 14, 2007
    risk 0.01cvss —epss 0.12

    Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296,…

  • CVE-2007-0219Feb 13, 2007
    risk 0.03cvss —epss 0.39

    Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.

  • CVE-2007-0905Feb 13, 2007
    risk 0.00cvss —epss 0.03

    PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.