Total
29548 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-3247 | 1 Virtuemart | 1 Virtuemart | 2025-04-09 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php. | |||||
CVE-2007-0254 | 1 Xine | 1 Xine-ui | 2025-04-09 | 10.0 HIGH | N/A |
Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors. | |||||
CVE-2007-3871 | 1 Deutsche Post | 1 Stampit Web | 2025-04-09 | 5.0 MEDIUM | N/A |
Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of service (stamp invalidation) via a SOAP request with an id value for a stamp that has not yet been printed. | |||||
CVE-2006-6358 | 1 Stefan Frech | 1 Online-bookmarks | 2025-04-09 | 7.5 HIGH | N/A |
SQL injection vulnerability in the login function in auth.inc in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to execute arbitrary SQL commands via the (1) username and possibly the (2) password parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-4147 | 1 Interspire | 1 Articlelive Nx | 2025-04-09 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to (1) AL_SANITIZE and (2) "Calling the constructor to make sure things are checked, safe mode, etc." | |||||
CVE-2007-1156 | 1 Man Machine Systems | 1 Jbrowser | 2025-04-09 | 7.5 HIGH | N/A |
JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/. | |||||
CVE-2006-6300 | 1 Cutephp | 1 Cutenews | 2025-04-09 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | |||||
CVE-2006-6023 | 1 Bloo | 1 Bloo | 2025-04-09 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in phoo.base.php in Bill Roberts Bloo 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the descriptorFileList parameter. NOTE: this issue is disputed by CVE since $descriptorFileList is used in a function definition within phoo.base.php | |||||
CVE-2007-2894 | 1 Bochs Project | 1 Bochs | 2025-04-09 | 2.1 LOW | N/A |
The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error. | |||||
CVE-2006-6254 | 1 Cahier De Textes | 1 Cahier De Textes | 2025-04-09 | 4.3 MEDIUM | N/A |
administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability. | |||||
CVE-2007-4249 | 1 Exportnation | 1 Exportnation Toolbar | 2025-04-09 | 4.3 MEDIUM | N/A |
The isChecked function in Toolbar.DLL in the ExportNation toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. | |||||
CVE-2007-3178 | 1 Zindizayn Okul Web Sistemi | 1 Zindizayn Okul Web Sistemi | 2025-04-09 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Zindizayn Okul Web Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) pass parameter to (a) mezungiris.asp or (b) ogretmenkontrol.asp. | |||||
CVE-2007-1745 | 2 Clam Anti-virus, Ifenslave | 2 Clamav, Ifenslave | 2025-04-09 | 7.1 HIGH | N/A |
The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-4279 | 1 Frontaccounting | 1 Frontaccounting | 2025-04-09 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | |||||
CVE-2006-6033 | 1 Sphpblog | 1 Sphpblog | 2025-04-09 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in Simple PHP Blog (SPHPBlog), probably 0.4.8, allow remote attackers to read arbitrary files and possibly include arbitrary PHP code via a .. (dot dot) sequence in the blog_theme parameter in (1) index.php, (2) add_cgi.php, (3) add_link.php, (4) login.php, (5) template.php, or (6) contact.php. | |||||
CVE-2007-3531 | 1 Gentoo | 2 Linux, Nvclock | 2025-04-09 | 6.6 MEDIUM | N/A |
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file. | |||||
CVE-2006-5607 | 1 Inca | 1 Im-204 Adsl Router | 2025-04-09 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in /cgi-bin/webcm in INCA IM-204 allows remote attackers to read arbitrary files via a "/./." (modified dot dot) sequences in the getpage parameter. | |||||
CVE-2007-1555 | 1 Minerva | 1 Minerva | 2025-04-09 | 7.5 HIGH | N/A |
SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter. | |||||
CVE-2007-0542 | 1 212cafe | 1 Guestbook | 2025-04-09 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter. | |||||
CVE-2008-0680 | 1 Microtik | 1 Routeros | 2025-04-09 | 7.8 HIGH | N/A |
SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request. |