Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-3049 | 1 Cisco | 1 Ios | 2017-10-03 | 4.9 MEDIUM | 5.5 MEDIUM |
Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot). | |||||
CVE-2010-3050 | 1 Cisco | 1 Ios | 2017-10-03 | 6.8 MEDIUM | 6.5 MEDIUM |
Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot). | |||||
CVE-2017-1551 | 1 Ibm | 1 Api Connect | 2017-10-03 | 5.8 MEDIUM | 6.1 MEDIUM |
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291. | |||||
CVE-2017-1555 | 1 Ibm | 1 Api Connect | 2017-10-03 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545. | |||||
CVE-2015-7318 | 1 Plone | 1 Plone | 2017-10-03 | 5.0 MEDIUM | 7.5 HIGH |
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses. | |||||
CVE-2015-5179 | 1 Freeipa | 1 Freeipa | 2017-10-03 | 5.0 MEDIUM | 7.5 HIGH |
FreeIPA might display user data improperly via vectors involving non-printable characters. | |||||
CVE-2009-2138 | 1 Tbdev | 1 Tbdev.net | 2017-09-28 | 4.3 MEDIUM | N/A |
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php or (2) the returnto parameter in a delete action to news.php. NOTE: this can be leveraged for cross-site scripting (XSS) by redirecting to a data: URI. | |||||
CVE-2009-0813 | 1 Imera | 1 Teamlinks | 2017-09-28 | 9.3 HIGH | N/A |
Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters. | |||||
CVE-2017-6269 | 2 Microsoft, Nvidia | 2 Windows, Gpu Driver | 2017-09-28 | 7.2 HIGH | 7.8 HIGH |
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is used without validation which may lead to denial of service or possible escalation of privileges. | |||||
CVE-2009-1045 | 1 Videolan | 1 Vlc Media Player | 2017-09-28 | 5.0 MEDIUM | N/A |
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action. | |||||
CVE-2009-1087 | 1 Pplive | 1 Pplive | 2017-09-28 | 9.3 HIGH | N/A |
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1232 | 1 Mozilla | 1 Firefox | 2017-09-28 | 4.3 MEDIUM | N/A |
Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected. | |||||
CVE-2009-1233 | 2 Apple, Microsoft | 2 Safari, Windows | 2017-09-28 | 4.3 MEDIUM | N/A |
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements. | |||||
CVE-2009-1234 | 1 Opera | 1 Opera Browser | 2017-09-28 | 4.3 MEDIUM | N/A |
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected. | |||||
CVE-2009-1369 | 1 Mozilo | 1 Mozilocms | 2017-09-28 | 5.0 MEDIUM | N/A |
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message. | |||||
CVE-2009-1446 | 1 Elkagroup | 1 Image Gallery | 2017-09-28 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1609 | 1 Battleblog | 1 Battle Blog | 2017-09-28 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | |||||
CVE-2009-1668 | 1 Typsoft | 1 Typsoft Ftp Server | 2017-09-28 | 4.0 MEDIUM | N/A |
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer. | |||||
CVE-2009-1669 | 1 Smarty | 1 Smarty | 2017-09-28 | 10.0 HIGH | N/A |
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1739 | 1 Phpeasycode | 1 Pad Site Scripts | 2017-09-28 | 7.5 HIGH | N/A |
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username. |