Vulnerabilities (CVE)

Total 259289 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6000 1 Kde 1 Konqueror 2024-02-04 5.0 MEDIUM N/A
KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.
CVE-2006-6772 1 W3m 1 W3m 2024-02-04 9.3 HIGH N/A
Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.
CVE-2007-1882 1 Hp 1 Mercury Quality Center 2024-02-04 6.5 MEDIUM N/A
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.
CVE-2006-6056 1 Linux 1 Linux Kernel 2024-02-04 4.9 MEDIUM N/A
Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.
CVE-2007-6490 1 Falcon 1 Series One Cms 2024-02-04 4.3 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.
CVE-2006-5327 2 Apple, Openbase International Ltd 2 Xcode, Openbase 2024-02-04 7.2 HIGH N/A
Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by OpenBase.
CVE-2007-1820 1 Nortel 2 Callpilot, Meridian Mail 2024-02-04 9.3 HIGH N/A
Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).
CVE-2008-0981 1 Spyce 1 Spyce 2024-02-04 6.4 MEDIUM N/A
Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
CVE-2006-5149 1 Openbiblio 1 Openbiblio 2024-02-04 7.5 HIGH N/A
Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.
CVE-2007-2349 1 Invision Power Services 1 Invision Power Board 2024-02-04 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.
CVE-2007-1663 2 Debian, Ekg 2 Debian Linux, Ekg 2024-02-04 5.0 MEDIUM N/A
Memory leak in the image message functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.
CVE-2006-3434 1 Microsoft 1 Office 2024-02-04 9.3 HIGH N/A
Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
CVE-2007-4748 1 Ppstream 1 Ppstream 2024-02-04 6.8 MEDIUM N/A
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitrary code via a long Logo parameter.
CVE-2007-1880 1 Kaspersky Lab 2 Kaspersky Anti-virus, Kaspersky Internet Security 2024-02-04 6.6 MEDIUM N/A
Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow.
CVE-2008-0250 1 Microsoft 1 Visual Interdev 2024-02-04 9.3 HIGH N/A
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.
CVE-2007-5282 1 Hitachi 3 Cosminexus Agent, Cosminexus Library Standard, Cosminexus Library Web 2024-02-04 4.3 MEDIUM N/A
Hitachi Cosminexus Agent 03-00 through 03-05, and Cosminexus Library Standard and Web Edition 04-00 and 04-01, might allow remote attackers to cause a denial of service (agent process crash) via invalid data from clients other than Cosminexus Manager.
CVE-2008-0235 1 Microsoft 1 Vfp Ole Server Activex Control 2024-02-04 10.0 HIGH N/A
The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.
CVE-2007-3685 1 Masuga Design 1 Unobtrusive Ajax Star Rating Bar 2024-02-04 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CVE-2008-0368 1 Ibm 1 Informix Dynamic Server 2024-02-04 7.2 HIGH N/A
onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
CVE-2006-6139 1 Sisfo Kampus 1 Sisfo Kampus 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.