Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3748 | 1 Tru-zone | 1 Nukeet | 2011-08-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter. | |||||
CVE-2005-3840 | 1 Omnistar Interactive | 1 Omnistar Live | 2011-08-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240. | |||||
CVE-2005-3881 | 1 Altantisfaq | 1 Altantis Knowledge Base Software | 2011-08-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. | |||||
CVE-2005-4073 | 1 Cfmagic | 1 Magic List Pro | 2011-08-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter. | |||||
CVE-2006-3960 | 1 X-scripts | 1 X-poll | 2011-08-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2007-0789 | 1 Mambo | 1 Mambo | 2011-08-04 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter. | |||||
CVE-2006-6297 | 1 Kde | 1 Kdegraphics | 2011-08-03 | 5.0 MEDIUM | N/A |
Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, allows remote attackers to cause a denial of service (stack consumption) via a crafted EXIF section in a JPEG file, which results in an infinite recursion. | |||||
CVE-2005-2930 | 1 Jed Wing | 1 Chm Lib | 2011-08-01 | 5.1 MEDIUM | N/A |
Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulnerability than CVE-2005-3318. | |||||
CVE-2006-2200 | 2 Mimms, Xine | 2 Mimms, Xine-lib | 2011-08-01 | 5.1 MEDIUM | N/A |
Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions. | |||||
CVE-2011-2185 | 1 Fabfile | 1 Fabric | 2011-08-01 | 4.4 MEDIUM | N/A |
Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a /tmp/fab.*.tar file or (2) certain other files in the top level of /tmp/. | |||||
CVE-2011-1339 | 1 Google | 1 Search Appliance | 2011-07-31 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-2959 | 1 7t | 1 Igss | 2011-07-31 | 10.0 HIGH | N/A |
Stack-based buffer overflow in the Open Database Connectivity (ODBC) service (Odbcixv9se.exe) in 7-Technologies Interactive Graphical SCADA System (IGSS) 9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet to TCP port 22202. | |||||
CVE-2011-2960 | 1 Sunwayland | 1 Forcecontrol | 2011-07-31 | 10.0 HIGH | N/A |
Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted URL. | |||||
CVE-2011-2961 | 1 Sunwayland | 1 Pnetpower | 2011-07-31 | 10.0 HIGH | N/A |
Heap-based buffer overflow in AngelServer.exe 6.0.11.3 in Sunway pNetPower allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UDP packet. | |||||
CVE-2011-2963 | 1 Progea | 1 Movicon | 2011-07-31 | 10.0 HIGH | N/A |
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651. | |||||
CVE-2011-2892 | 1 Joomla | 1 Joomla\! | 2011-07-28 | 4.3 MEDIUM | N/A |
Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site. | |||||
CVE-2011-2956 | 1 Azeotech | 1 Daqfactory | 2011-07-28 | 7.8 HIGH | N/A |
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal. | |||||
CVE-2010-1938 | 2 Freebsd, Nrl | 2 Freebsd, Opie | 2011-07-28 | 9.3 HIGH | N/A |
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd. | |||||
CVE-2011-2488 | 1 Joomla | 1 Joomla\! | 2011-07-27 | 5.0 MEDIUM | N/A |
Joomla! before 1.5.23 does not properly check for errors, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2011-1152 | 2011-07-27 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3712. Reason: This candidate is a duplicate of CVE-2010-3712. Notes: All CVE users should reference CVE-2010-3712 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |