Total
10018 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-6433 | 1 Jboss | 1 Seam | 2024-02-04 | 7.5 HIGH | N/A |
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order parameter. | |||||
CVE-2007-3711 | 1 3com | 1 Tippingpoint Ips Tos | 2024-02-04 | 7.5 HIGH | N/A |
Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid detection by sending certain fragmented packets. | |||||
CVE-2007-4905 | 1 Auracms | 1 Auracms | 2024-02-04 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/. | |||||
CVE-2007-4130 | 1 Redhat | 2 Enterprise Linux, Enterprise Linux Desktop | 2024-02-04 | 7.2 HIGH | N/A |
The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_mempolicy in an MPOL_BIND operation. | |||||
CVE-2008-0251 | 1 Photopost | 1 Photopost Vbgallery | 2024-02-04 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors. | |||||
CVE-2007-1155 | 1 Webspell | 1 Webspell | 2024-02-04 | 4.6 MEDIUM | N/A |
Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED. | |||||
CVE-2008-0473 | 1 Web Wiz | 1 Rich Text Editor | 2024-02-04 | 6.4 MEDIUM | N/A |
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors. | |||||
CVE-2007-5130 | 1 Boesch-it | 1 Simpgb | 2024-02-04 | 4.3 MEDIUM | N/A |
SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reveals the path in various error messages. | |||||
CVE-2006-4936 | 1 Moodle | 1 Moodle | 2024-02-04 | 10.0 HIGH | N/A |
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors. | |||||
CVE-2008-0277 | 1 Drupal | 1 Fileshare Module | 2024-02-04 | 8.5 HIGH | N/A |
Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors. | |||||
CVE-2007-2509 | 1 Php | 1 Php | 2024-02-04 | 2.6 LOW | N/A |
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands. | |||||
CVE-2006-7070 | 1 Etomite | 1 Etomite | 2024-02-04 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files via an nfile[] parameter with a filename that contains a .php extension followed by a valid image extension such as .gif or .jpg, then calling the rename function. | |||||
CVE-2007-5563 | 1 Virtuemart | 1 Virtuemart | 2024-02-04 | 7.5 HIGH | N/A |
Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors. | |||||
CVE-2007-1995 | 1 Quagga | 1 Quagga | 2024-02-04 | 6.3 MEDIUM | N/A |
bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read. | |||||
CVE-2007-1693 | 1 Yate | 1 Yet Another Telephony Engine | 2024-02-04 | 7.8 HIGH | N/A |
The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter. | |||||
CVE-2008-1265 | 1 Linksys | 1 Wrt54g | 2024-02-04 | 7.8 HIGH | N/A |
The Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface. | |||||
CVE-2007-3753 | 1 Apple | 2 Iphone, Iphone Os | 2024-02-04 | 7.5 HIGH | N/A |
Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Service Discovery Protocol (SDP) packets, related to insufficient input validation. | |||||
CVE-2008-0171 | 1 Boost | 2 Boost, Boost Regex Library | 2024-02-04 | 5.0 MEDIUM | N/A |
regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression. | |||||
CVE-2007-1426 | 1 Astrocam | 1 Astrocam | 2024-02-04 | 7.8 HIGH | N/A |
The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue." | |||||
CVE-2007-5119 | 1 Jspwiki | 1 Jspwiki | 2024-02-04 | 4.3 MEDIUM | N/A |
JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/. |