Total
29519 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-4806 | 1 Enlightenment | 1 Imlib2 | 2025-04-09 | 5.1 MEDIUM | N/A |
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images. | |||||
CVE-2007-3961 | 1 Fsp | 1 C Library | 2025-04-09 | 5.0 MEDIUM | N/A |
Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added. | |||||
CVE-2006-6514 | 1 Flippet.org | 1 Winamp Web Interface | 2025-04-09 | 3.5 LOW | N/A |
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder. | |||||
CVE-2007-2249 | 1 Phorum | 1 Phorum | 2025-04-09 | 6.5 MEDIUM | N/A |
include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array. | |||||
CVE-2007-4944 | 1 Opera | 1 Opera Browser | 2025-04-09 | 5.0 MEDIUM | N/A |
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript. | |||||
CVE-2006-6920 | 1 Nucleus Cms | 1 Nucleus Cms | 2025-04-09 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php. | |||||
CVE-2008-0708 | 1 Hp | 3 442084-b21, 442085-b21, Proliant | 2025-04-09 | 4.6 MEDIUM | N/A |
HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection. | |||||
CVE-2007-0377 | 1 Xoops | 1 Xoops | 2025-04-09 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors. | |||||
CVE-2006-5210 | 1 Ciphertrust | 1 Ironmail | 2025-04-09 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded "../" sequences ("%252e%252e/"). | |||||
CVE-2007-1911 | 1 Microsoft | 1 Word | 2025-04-09 | 7.1 HIGH | N/A |
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow. | |||||
CVE-2009-0618 | 1 Cisco | 1 Application Networking Manager | 2025-04-09 | 8.5 HIGH | N/A |
Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files. | |||||
CVE-2007-0855 | 1 Rarlab | 1 Unrar | 2025-04-09 | 6.8 MEDIUM | N/A |
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive. | |||||
CVE-2006-6784 | 1 Netbula | 1 Anyboard | 2025-04-09 | 7.5 HIGH | N/A |
SQL injection vulnerability in Netbula Anyboard allows remote attackers to execute arbitrary SQL commands via the user name in the login form. | |||||
CVE-2007-2468 | 1 Hp | 1 Openvms | 2025-04-09 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in HP OpenVMS for Integrity Servers 8.2-1 and 8.3 allows local users to cause a denial of service (crash) via "Program actions relating to exceptions." | |||||
CVE-2007-4489 | 1 Ecentrex | 1 Voip Client Module | 2025-04-09 | 6.8 MEDIUM | N/A |
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method. | |||||
CVE-2009-1808 | 1 Microsoft | 1 Windows Xp | 2025-04-09 | 4.9 MEDIUM | N/A |
Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call. | |||||
CVE-2007-0624 | 1 Maxdev | 1 Mdpro | 2025-04-09 | 5.0 MEDIUM | N/A |
user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation. | |||||
CVE-2007-2471 | 1 Sendcard | 1 Sendcard | 2025-04-09 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter. | |||||
CVE-2006-5150 | 1 Openbiblio | 1 Openbiblio | 2025-04-09 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2007-0068 | 1 Ibm | 1 Lotus Domino | 2025-04-09 | 9.3 HIGH | N/A |
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database. |