Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3495 | 1 Measuresoft | 1 Scadapro | 2012-02-13 | 10.0 HIGH | N/A |
Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command. | |||||
CVE-2011-3496 | 1 Measuresoft | 1 Scadapro | 2012-02-13 | 10.0 HIGH | N/A |
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command. | |||||
CVE-2011-3497 | 1 Measuresoft | 1 Scadapro | 2012-02-13 | 10.0 HIGH | N/A |
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method. | |||||
CVE-2011-3645 | 1 Newgensoft | 1 Omnidocs | 2012-02-13 | 7.5 HIGH | N/A |
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user. | |||||
CVE-2011-2412 | 1 Hp | 1 Business Service Automation Essentials | 2012-02-13 | 10.0 HIGH | N/A |
Unspecified vulnerability in HP Business Service Automation (BSA) Essentials 2.01 allows remote attackers to execute arbitrary code via unknown vectors. | |||||
CVE-2011-2443 | 1 Adobe | 1 Photoshop Elements | 2012-02-13 | 9.3 HIGH | N/A |
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296. | |||||
CVE-2011-2628 | 1 Opera | 1 Opera Browser | 2012-02-13 | 10.0 HIGH | N/A |
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload. | |||||
CVE-2011-2739 | 1 Emc | 1 Documentum Eroom | 2012-02-13 | 8.5 HIGH | N/A |
The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file. | |||||
CVE-2011-1774 | 2 Apple, Microsoft | 7 Mac Os X, Mac Os X Server, Safari and 4 more | 2012-02-13 | 8.8 HIGH | N/A |
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425. | |||||
CVE-2011-2023 | 1 Squirrelmail | 1 Squirrelmail | 2012-02-13 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in functions/mime.php in SquirrelMail before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via a crafted STYLE element in an e-mail message. | |||||
CVE-2011-0182 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-02-13 | 7.2 HIGH | N/A |
The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry. | |||||
CVE-2010-4834 | 1 Oneorzero | 1 Aims | 2012-02-13 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-4835 | 1 Oneorzero | 1 Aims | 2012-02-13 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action. | |||||
CVE-2010-4837 | 2 Extensiondepot, Joomla | 2 Com Jsupport, Joomla\! | 2012-02-13 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-4838 | 2 Extensiondepot, Joomla | 2 Com Jsupport, Joomla\! | 2012-02-13 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php. | |||||
CVE-2010-4850 | 1 Diferior | 1 Diferior | 2012-02-13 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php. | |||||
CVE-2010-4851 | 1 Eclime | 1 Eclime | 2012-02-13 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php. | |||||
CVE-2010-4852 | 1 Eclime | 1 Eclime | 2012-02-13 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action. | |||||
CVE-2010-4855 | 1 Aspindir | 1 Xweblog | 2012-02-13 | 7.5 HIGH | N/A |
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter. | |||||
CVE-2010-4858 | 1 Joerg Risse | 1 Dnet Live-stats | 2012-02-13 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter. |