Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-2182 | 1 Macromedia | 1 Jrun | 2008-09-04 | 7.5 HIGH | N/A |
Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server. | |||||
CVE-2004-2683 | 1 Intersystems | 1 Cache | 2008-09-04 | 2.1 LOW | N/A |
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server. | |||||
CVE-2004-2684 | 1 Intersystems | 1 Cache Database | 2008-09-04 | 2.1 LOW | N/A |
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files under (a) Dev\studio\templates and (b) Devuser\studio\templates. | |||||
CVE-2004-2687 | 2 Apple, Samba | 2 Xcode, Samba | 2008-09-04 | 9.3 HIGH | N/A |
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks. | |||||
CVE-2004-2700 | 1 Aspdotnetstorefront | 1 Aspdotnetstorefront | 2008-09-04 | 9.0 HIGH | N/A |
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. | |||||
CVE-2004-2706 | 1 Phrozensmoke | 1 Gyach Enhanced | 2008-09-04 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages. | |||||
CVE-2005-1812 | 1 Futuresoft | 1 Tftp Server 2000 | 2008-09-04 | 10.0 HIGH | N/A |
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet. | |||||
CVE-2005-1813 | 1 Futuresoft | 1 Tftp Server 2000 | 2008-09-04 | 7.8 HIGH | N/A |
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences. | |||||
CVE-2005-4849 | 1 Apache | 1 Derby | 2008-09-04 | 5.0 MEDIUM | N/A |
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain sensitive information. | |||||
CVE-2006-6975 | 1 Centipaid | 1 Centipaid | 2008-09-04 | 5.1 MEDIUM | N/A |
** DISPUTED ** PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter. NOTE: this issue has been disputed by CVE and multiple third parties, who state that $class_pwd is set to a static value before the relevant include statement. | |||||
CVE-2006-7221 | 1 Fsp | 1 C Library | 2008-09-04 | 5.0 MEDIUM | N/A |
Multiple off-by-one errors in fsplib.c in fsplib before 0.8 allow attackers to cause a denial of service via unspecified vectors involving the (1) name and (2) d_name entry attributes. | |||||
CVE-2006-7229 | 1 Ubuntu | 1 Linux Kernel | 2008-09-04 | 7.8 HIGH | N/A |
The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to cause a denial of service (machine crash) via a flood of network traffic. | |||||
CVE-2007-0342 | 2 Apple, Omnigroup | 4 Mac Os X, Safari, Webkit and 1 more | 2008-09-04 | 4.3 MEDIUM | N/A |
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019. | |||||
CVE-2007-1383 | 1 Php | 1 Php | 2008-09-04 | 10.0 HIGH | N/A |
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286. | |||||
CVE-2007-1966 | 1 Exv2 | 1 Content Management System | 2008-09-04 | 5.0 MEDIUM | N/A |
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | |||||
CVE-2007-3650 | 1 Mywebland | 1 Mybloggie | 2008-09-04 | 5.0 MEDIUM | N/A |
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages. | |||||
CVE-2007-3651 | 1 Fascript | 1 Faname | 2008-09-04 | 4.3 MEDIUM | N/A |
class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message. | |||||
CVE-2007-3652 | 1 Fascript | 1 Faname | 2008-09-04 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328. | |||||
CVE-2007-3967 | 1 Dirlist | 1 Dirlist Php | 2008-09-04 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot) in the folder parameter. | |||||
CVE-2007-3968 | 1 Dirlist | 1 Dirlist Php | 2008-09-04 | 5.0 MEDIUM | N/A |
index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name. |