Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-2428 | 1 Goahead | 1 Goahead Webserver | 2009-07-22 | 5.0 MEDIUM | N/A |
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data. | |||||
CVE-2009-2386 | 1 Awingsoft | 1 Awakening Winds3d Viewer Plugin | 2009-07-12 | 9.3 HIGH | N/A |
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method. | |||||
CVE-2008-4388 | 1 Symantec | 1 Appstream Client | 2009-05-17 | 9.3 HIGH | N/A |
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods. | |||||
CVE-2009-1361 | 1 Gscripts | 1 Dns Tools | 2009-04-22 | 10.0 HIGH | N/A |
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-1149 | 1 Phpmyadmin | 1 Phpmyadmin | 2009-04-15 | 7.5 HIGH | N/A |
CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters. | |||||
CVE-2009-1254 | 1 James Stone | 1 Tunapie | 2009-04-15 | 6.8 MEDIUM | N/A |
James Stone Tunapie 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a stream URL. | |||||
CVE-2002-1979 | 1 Watchguard | 3 Legacy Rssa, Soho, Vclass | 2009-04-02 | 7.5 HIGH | N/A |
WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server. | |||||
CVE-2009-1082 | 1 Sun | 1 Java System Identity Manager | 2009-03-25 | 9.0 HIGH | N/A |
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs. | |||||
CVE-2009-0027 | 1 Redhat | 1 Jboss Enterprise Application Platform | 2009-03-20 | 5.0 MEDIUM | N/A |
The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request. | |||||
CVE-2009-0609 | 1 Sun | 1 Java System Directory Server | 2009-02-17 | 7.8 HIGH | N/A |
Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests. | |||||
CVE-2003-1568 | 2 Goahead, Goahead Software | 2 Goahead Webserver, Goahead Webserver | 2009-02-08 | 5.0 MEDIUM | N/A |
GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function. | |||||
CVE-2003-1569 | 2 Goahead, Microsoft | 4 Goahead Webserver, Windows 95, Windows 98 and 1 more | 2009-02-08 | 5.0 MEDIUM | N/A |
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385. | |||||
CVE-2002-2429 | 1 Goahead | 1 Goahead Webserver | 2009-02-06 | 5.0 MEDIUM | N/A |
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header. | |||||
CVE-2008-6058 | 1 Syslserve | 1 Syslserve | 2009-02-04 | 5.0 MEDIUM | N/A |
Syslserve 1.058 and earlier, and probably 1.059, allows remote attackers to cause a denial of service (hang) via a crafted UDP Syslog packet. | |||||
CVE-2008-4640 | 1 Sentex | 1 Jhead | 2008-12-02 | 3.6 LOW | N/A |
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character. | |||||
CVE-2008-4641 | 1 Sentex | 1 Jhead | 2008-12-02 | 10.0 HIGH | N/A |
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input. | |||||
CVE-2007-6689 | 1 Menalto | 1 Gallery | 2008-11-14 | 7.5 HIGH | N/A |
Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module. | |||||
CVE-2007-6010 | 1 Pioneers | 1 Pioneers | 2008-11-14 | 7.8 HIGH | N/A |
Unspecified vulnerability in pioneers (formerly gnocatan) 0.11.3 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors that trigger an assert error. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-5933. | |||||
CVE-2007-6093 | 1 Ingate | 2 Ingate Firewall, Ingate Siparator | 2008-11-14 | 7.1 HIGH | N/A |
The SRTP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (kernel crash) via an RTCP index that is "much more than expected." | |||||
CVE-2007-6094 | 1 Ingate | 2 Ingate Firewall, Ingate Siparator | 2008-11-14 | 4.3 MEDIUM | N/A |
The IPsec module in the VPN component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (module crash) via an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS). |