VYPR

Vendor CVEs

EMule X Ray

All CVEs

34 total · sorted by risk
  • CVE-2019-1000023CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL…

  • CVE-2016-8863CriMar 7, 2017
    risk 0.64cvss 9.8epss 0.08

    Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the…

  • CVE-2012-10056HigAug 13, 2025
    risk 0.60cvss epss 0.01

    PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is…

  • CVE-2020-15395HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.01

    In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).

  • CVE-2020-37088HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.03

    School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to…

  • CVE-2023-48161HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c

  • CVE-2017-11722MedJul 28, 2017
    risk 0.42cvss 6.5epss 0.02

    The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This…

  • CVE-2024-34749MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.01

    Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.

  • CVE-2019-8938MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.

  • CVE-2023-46316MedOct 25, 2023
    risk 0.36cvss 5.5epss 0.00

    In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

  • CVE-2012-1614Sep 4, 2012
    risk 0.04cvss epss 0.09

    Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid…

  • CVE-2011-5185Sep 20, 2012
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

  • CVE-2008-3714Aug 19, 2008
    risk 0.03cvss epss 0.06

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

  • CVE-2008-2298May 18, 2008
    risk 0.03cvss epss 0.03

    Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.

  • CVE-2008-0501Jan 30, 2008
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.

  • CVE-2007-1572Mar 21, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2002-2362Dec 31, 2002
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

  • CVE-2005-4837Dec 31, 2005
    risk 0.01cvss epss 0.10

    snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect…

  • CVE-2019-11372MedApr 20, 2019
    risk 0.00cvss 6.5epss 0.03

    An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.

  • CVE-2015-8100Nov 10, 2015
    risk 0.00cvss epss 0.01

    The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.

  • CVE-2012-5965Jan 31, 2013
    risk 0.00cvss epss 0.37

    Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code via a long DeviceType (aka…

  • CVE-2008-6161Feb 18, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-6113Feb 11, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SemanticScuttle before 0.90 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the (1) username and (2) profile page.

  • CVE-2008-2503May 29, 2008
    risk 0.00cvss epss 0.01

    Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.

  • CVE-2008-2502May 29, 2008
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the web server in eMule X-Ray before 1.4 allows remote attackers to trigger memory corruption via unknown attack vectors.

  • CVE-2007-6640Jan 4, 2008
    risk 0.00cvss epss 0.01

    Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GM_addStyle, (2) GM_log, (3) GM_openInTab,…

  • CVE-2007-1466Mar 16, 2007
    risk 0.00cvss epss 0.03

    Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted…

  • CVE-2007-1137Mar 2, 2007
    risk 0.00cvss epss 0.01

    putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain…

  • CVE-2007-1135Mar 2, 2007
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.

  • CVE-2007-0975Feb 16, 2007
    risk 0.00cvss epss 0.01

    Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.

  • CVE-2005-4286Dec 16, 2005
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.

  • CVE-2002-2364Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.

  • CVE-2002-0490Aug 12, 2002
    risk 0.00cvss epss 0.03

    Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.

  • CVE-2001-0234May 3, 2001
    risk 0.00cvss epss 0.02

    NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.