Total
29099 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2013-2276 | 1 Ffmpeg | 1 Ffmpeg | 2024-09-17 | N/A |
The avcodec_decode_audio4 function in utils.c in libavcodec in FFmpeg before 1.1.3 does not verify the decoding state before proceeding with certain skip operations, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted audio data. | ||||
CVE-2010-5245 | 1 Tracker-software | 1 Pdf-xchange Viewer | 2024-09-17 | N/A |
Untrusted search path vulnerability in PDF-XChange Viewer 2.0 Build 54.0 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information. | ||||
CVE-2005-4673 | 1 Inicom Networks | 1 Ioftpd | 2024-09-17 | N/A |
ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames. | ||||
CVE-2014-2861 | 1 Paperthin | 1 Commonspot Content Server | 2024-09-17 | N/A |
Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string. | ||||
CVE-2010-5249 | 1 Sophos | 2 Free Encryption, Safeguard Privatecrypto | 2024-09-17 | N/A |
Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||||
CVE-2003-1259 | 1 Globalscape | 1 Cuteftp | 2024-09-17 | N/A |
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner. | ||||
CVE-2005-3292 | 1 Xeobook | 1 Xeobook | 2024-09-17 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>. | ||||
CVE-2002-1835 | 1 Xerox | 2 Docutech 6110, Docutech 6115 | 2024-09-17 | N/A |
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device. | ||||
CVE-2005-1433 | 1 Hp | 1 Openview Event Correlation Services | 2024-09-17 | N/A |
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code. | ||||
CVE-2013-2580 | 1 Tp-link | 5 Lm Firmware, Tl-sc3130, Tl-sc3130g and 2 more | 2024-09-17 | N/A |
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd directory. | ||||
CVE-2005-2504 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2024-09-17 | N/A |
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid. | ||||
CVE-2006-4941 | 1 Moodle | 1 Moodle | 2024-09-17 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php. | ||||
CVE-2018-25029 | 1 Silabs | 10 Zgm130s037hgn, Zgm130s037hgn Firmware, Zgm2305a27hgn and 7 more | 2024-09-17 | 8.1 High |
The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept and spoof traffic. | ||||
CVE-2005-2153 | 1 Osticket | 1 Osticket Sts | 2024-09-17 | N/A |
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable. | ||||
CVE-2001-1535 | 1 Open Source Development Network | 1 Slashcode | 2024-09-17 | N/A |
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack. | ||||
CVE-2005-0576 | 1 Sun | 1 Solaris | 2024-09-17 | N/A |
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files. | ||||
CVE-2005-1659 | 1 Myserver | 1 Myserver | 2024-09-17 | N/A |
Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by an onmouseover event. | ||||
CVE-2007-3616 | 1 Vtiger | 1 Vtiger Crm | 2024-09-17 | N/A |
index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module. | ||||
CVE-2006-0463 | 1 Ideosoft Design | 1 Ideocontent Manager | 2024-09-17 | N/A |
Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php. | ||||
CVE-2002-1884 | 1 Py-membres | 1 Py-membres | 2024-09-17 | N/A |
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin". |