Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-7205 | 1 Virtuemart | 1 Virtuemart | 2017-08-16 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file. | |||||
CVE-2009-0661 | 1 Flashtux | 1 Weechat | 2017-08-16 | 5.0 MEDIUM | N/A |
Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read. | |||||
CVE-2008-7135 | 1 Icq | 1 Icq Toolbar | 2017-08-16 | 4.3 MEDIUM | N/A |
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136. | |||||
CVE-2008-6171 | 1 Drupal | 1 Drupal | 2017-08-16 | 9.3 HIGH | N/A |
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header. | |||||
CVE-2008-6207 | 1 Phpg Upload | 1 Phpg Upload | 2017-08-16 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6298 | 1 Rocketeer.dip | 1 Sisapilocation | 2017-08-16 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function." | |||||
CVE-2008-6504 | 2 Apache, Opensymphony | 2 Struts, Xwork | 2017-08-16 | 5.0 MEDIUM | N/A |
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character. | |||||
CVE-2008-6547 | 1 Formencode | 1 Formencode | 2017-08-16 | 7.5 HIGH | N/A |
schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors. | |||||
CVE-2008-6568 | 1 Yehe | 1 Yehe | 2017-08-16 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in Yehe 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the envoyer feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6662 | 2 Avg, Linux | 2 Avg Anti-virus, Linux | 2017-08-16 | 4.3 MEDIUM | N/A |
AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption. | |||||
CVE-2008-6676 | 1 Quickersite | 1 Quickersite | 2017-08-16 | 5.0 MEDIUM | N/A |
QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message. | |||||
CVE-2008-6962 | 1 Avira | 4 Antivir, Antivir Personal, Antivir Professional and 1 more | 2017-08-16 | 7.2 HIGH | N/A |
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer. | |||||
CVE-2008-7037 | 2 Itn, Microsoft | 2 Itn News Gadget, Windows Vista | 2017-08-16 | 7.5 HIGH | N/A |
The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response. | |||||
CVE-2008-7112 | 1 Kyoceramita | 1 Scanner File Utility | 2017-08-16 | 5.0 MEDIUM | N/A |
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request. | |||||
CVE-2017-2442 | 1 Apple | 2 Iphone Os, Safari | 2017-08-15 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | |||||
CVE-2016-1484 | 1 Cisco | 1 Webex Meetings Server | 2017-08-15 | 5.0 MEDIUM | 7.5 HIGH |
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724. | |||||
CVE-2016-1478 | 1 Cisco | 1 Ios | 2017-08-15 | 7.8 HIGH | 7.5 HIGH |
Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619. | |||||
CVE-2016-5251 | 1 Mozilla | 1 Firefox | 2017-08-15 | 4.3 MEDIUM | 4.3 MEDIUM |
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL. | |||||
CVE-2016-1365 | 1 Cisco | 1 Application Policy Infrastructure Controller Enterprise Module | 2017-08-15 | 8.5 HIGH | 8.8 HIGH |
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507. | |||||
CVE-2016-1419 | 1 Cisco | 2 Aironet, Aironet Access Point Software | 2017-08-15 | 6.8 MEDIUM | 8.1 HIGH |
Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803. |