Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-7411 | 1 Php | 1 Php | 2017-07-29 | 7.5 HIGH | 9.8 CRITICAL |
ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that references a partially constructed object. | |||||
CVE-2016-7457 | 1 Vmware | 1 Vrealize Operations | 2017-07-29 | 8.0 HIGH | 10.0 CRITICAL |
VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors. | |||||
CVE-2007-6028 | 1 Componentone | 1 Flexgrid | 2017-07-28 | 6.8 MEDIUM | N/A |
Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values. | |||||
CVE-2007-6035 | 1 Cacti | 1 Cacti | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter. | |||||
CVE-2007-6041 | 1 Rigs Of Rogs | 1 Rigs Of Rogs | 2017-07-28 | 7.5 HIGH | N/A |
Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code by sending a nickname, then a vehicle name in a MSG2_USE_VEHICLE message, in which the combined length triggers the overflow. | |||||
CVE-2007-6100 | 1 Phpmyadmin | 1 Phpmyadmin | 2017-07-28 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in libraries/auth/cookie.auth.lib.php in phpMyAdmin before 2.11.2.2, when logins are authenticated with the cookie auth_type, allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter to index.php, a different vulnerability than CVE-2005-0992. | |||||
CVE-2007-6101 | 1 Code-crafters | 1 Ability Mail Server | 2017-07-28 | 4.0 MEDIUM | N/A |
Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages. | |||||
CVE-2007-6103 | 1 Ihu | 1 I Hear U | 2017-07-28 | 5.0 MEDIUM | N/A |
I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size field in its header, which is improperly handled by the Receiver::processPacket function; and (2) a denial of service (daemon crash) via an (a) IHU_INFO_INIT or a (b) IHU_INFO_RING packet that does not specify the mode, which is improperly handled by the Player::ring function in Player.cpp. | |||||
CVE-2007-6104 | 1 Filemaker | 2 Filemaker, Filemaker Server | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2007-6122 | 1 Irc Services | 1 Irc Services | 2017-07-28 | 5.0 MEDIUM | N/A |
The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-6140 | 1 Dora Emlak | 1 Dora Emlak | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Dora Emlak 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) emlak_detay.asp and (b) haber_detay.asp, the (2) kategori parameter to (c) kategorisirala.asp, and the (3) tip parameter to (d) tipsirala.asp. | |||||
CVE-2007-6142 | 1 Salims Softhouse | 1 Jaf Cms | 2017-07-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) show parameter to index.php and the (2) print parameter to print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-6145 | 1 Hitachi | 1 Jp1 File Transmission Server | 2017-07-28 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vectors. | |||||
CVE-2007-6149 | 1 Adobe | 2 Connect Enterprise Server, Flash Media Server 2 | 2017-07-28 | 10.0 HIGH | N/A |
Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation. | |||||
CVE-2007-6150 | 1 Freebsd | 1 Freebsd | 2017-07-28 | 2.1 LOW | N/A |
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values. | |||||
CVE-2007-6169 | 1 Gouae | 1 Dwd Realty | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-2007-6163. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-6174 | 1 Phpdevshell | 1 Phpdevshell | 2017-07-28 | 8.5 HIGH | N/A |
PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-6175 | 1 Lhaplus | 1 Lhaplus | 2017-07-28 | 6.6 MEDIUM | N/A |
Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector than CVE-2007-5048. | |||||
CVE-2007-6180 | 1 Sun | 1 Solaris | 2017-07-28 | 7.6 HIGH | N/A |
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors. | |||||
CVE-2007-6182 | 1 Growth | 1 Ispmanager | 2017-07-28 | 7.2 HIGH | N/A |
The responder program in ISPsystem ISPmanager (aka ISPmgr) 4.2.15.1 allows local users to gain privileges via shell metacharacters in command line arguments. |