Total
259287 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-1491 | 1 Avaya | 4 S8300, S8500, S8700 and 1 more | 2024-02-04 | 5.2 MEDIUM | N/A |
Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties. | |||||
CVE-2008-0007 | 1 Linux | 1 Linux Kernel | 2024-02-04 | 7.2 HIGH | N/A |
Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset. | |||||
CVE-2008-0255 | 1 Igamingcms | 1 Igaming Cms | 2024-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter. | |||||
CVE-2007-3271 | 1 Yourfreescreamer | 1 Yourfreescreamer | 2024-02-04 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter. | |||||
CVE-2007-4921 | 1 Ajax | 1 File Browser | 2024-02-04 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter. | |||||
CVE-2007-6268 | 1 Xigla | 1 Absolute News Manager.net | 2024-02-04 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter. | |||||
CVE-2007-4312 | 1 Php Blue Dragon | 1 Php Blue Dragon Cms | 2024-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action. | |||||
CVE-2007-1234 | 1 Bj Sintay | 1 Sitex | 2024-02-04 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php. | |||||
CVE-2008-1166 | 1 Flyspray | 1 Flyspray | 2024-02-04 | 5.0 MEDIUM | N/A |
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames. | |||||
CVE-2007-3247 | 1 Virtuemart | 1 Virtuemart | 2024-02-04 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php. | |||||
CVE-2007-3462 | 1 Sofaware | 1 Safe At Office 500 Utm | 2024-02-04 | 6.0 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network. | |||||
CVE-2007-6633 | 1 Netbizcity | 1 Faqmasterflexplus | 2024-02-04 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to inject arbitrary web script or HTML via (1) the cat_name parameter to faq.php; and unspecified parameters to the (2) add categories, (3) edit categories, (4) delete categories, (5) add faq, (6) edit faq, and (7) delete faq Admin scripts. | |||||
CVE-2007-6095 | 1 Ingate | 2 Ingate Firewall, Ingate Siparator | 2024-02-04 | 4.0 MEDIUM | N/A |
The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to receive messages intended for other users. | |||||
CVE-2007-1586 | 1 Zyxel | 1 Zynos | 2024-02-04 | 7.8 HIGH | N/A |
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol. | |||||
CVE-2007-5571 | 1 Cisco | 1 Firewall Services Module | 2024-02-04 | 6.8 MEDIUM | N/A |
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536. | |||||
CVE-2007-4817 | 1 Detodas | 1 Restaurante Component For Joomla | 2024-02-04 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/. | |||||
CVE-2007-6619 | 1 Atlassian | 1 Jira | 2024-02-04 | 7.5 HIGH | N/A |
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language. | |||||
CVE-2006-6801 | 1 Sh-news | 1 Sh-news | 2024-02-04 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter. | |||||
CVE-2006-5532 | 1 Xoops | 1 Xoops Rmsoft Gallery System | 2024-02-04 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT Gallery System 2.0 allows remote attackers to inject arbitrary web script or HTML via the kw parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-0273 | 1 Drupal | 1 Drupal | 2024-02-04 | 4.3 MEDIUM | N/A |
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism. |