Vulnerabilities (CVE)

Total 259221 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0355 1 Phpecho Cms 1 Phpecho Cms 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.
CVE-2007-1151 1 Lovecms 1 Lovecms 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.
CVE-2006-6042 1 Phpwebthings 1 Phpwebthings 2024-02-04 6.8 MEDIUM N/A
PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_bottom parameter.
CVE-2007-3258 1 Vincent Hor 1 Calendarix 2024-02-04 5.0 MEDIUM N/A
calendar.php in Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via large values to the (1) year and (2) month parameters, which causes negative values to be passed to the mktime library call, and reveals the installation path in the error message.
CVE-2007-3717 1 Sun 1 Sunos 2024-02-04 6.9 MEDIUM N/A
rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.
CVE-2006-6536 1 Cilem 1 Cilem Haber 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-1613 1 Mpm Chat 1 Mpm Chat 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.
CVE-2008-0187 1 Spacial Audio Solutions 1 Samphpweb 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
CVE-2007-3522 1 Sphpell 1 Sphpell 2024-02-04 6.8 MEDIUM N/A
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.
CVE-2006-4154 1 Apache 1 Http Server 2024-02-04 6.8 MEDIUM N/A
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
CVE-2008-0039 1 Apple 2 Mac Os X, Mail 2024-02-04 6.8 MEDIUM N/A
Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.
CVE-2007-1347 1 Microsoft 3 Windows 2000, Windows Explorer, Windows Xp 2024-02-04 7.1 HIGH N/A
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
CVE-2008-0846 2 Joomla, Mambo 2 Com Profile, Com Profile 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.
CVE-2007-3740 1 Linux 1 Linux Kernel 2024-02-04 4.4 MEDIUM N/A
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.
CVE-2008-0332 1 Aria 1 Aria 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
CVE-2007-6112 1 Wireshark 1 Wireshark 2024-02-04 10.0 HIGH N/A
Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
CVE-2006-6118 1 Mmgallery 1 Mmgallery 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2007-3309 1 Simple Machines 1 Simple Machines Forum 2024-02-04 7.5 HIGH N/A
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.
CVE-2006-6612 1 Phpmycms 1 Phpmycms 2024-02-04 7.5 HIGH N/A
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath_start parameter.
CVE-2007-5666 1 Adobe 2 Acrobat, Acrobat Reader 2024-02-04 6.2 MEDIUM N/A
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.