Total
28799 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-0403 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop. | |||||
CVE-2007-2385 | 1 Yahoo | 1 Ui Library | 2024-02-14 | 5.0 MEDIUM | N/A |
The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | |||||
CVE-2005-1459 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error). | |||||
CVE-2000-0274 | 1 Bray Systems | 1 Linux Trustees | 2024-02-14 | 2.1 LOW | N/A |
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name. | |||||
CVE-2006-3957 | 1 Bosdev | 1 Bosdates | 2024-02-14 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter. | |||||
CVE-2006-1381 | 1 Trend Micro | 1 Officescan | 2024-02-14 | 10.0 HIGH | N/A |
Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe. | |||||
CVE-2005-3947 | 1 Sergey Korostel | 1 Php Upload Center | 2024-02-14 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter. | |||||
CVE-2006-6935 | 1 Portix-php | 1 Portix-php | 2024-02-14 | 7.5 HIGH | N/A |
SQL injection vulnerability in the login component in Portix-PHP 0.4.2 allows remote attackers to execute arbitrary SQL commands via the username and passwd (password) fields. | |||||
CVE-2005-3248 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the X11 dissector in Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (divide-by-zero) via unknown vectors. | |||||
CVE-2000-0707 | 1 Pccs-linux | 1 Mysqldatabase Admin Tool | 2024-02-14 | 7.5 HIGH | N/A |
PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password. | |||||
CVE-2004-0633 | 4 Ethereal Group, Gentoo, Mandrakesoft and 1 more | 5 Ethereal, Linux, Mandrake Linux and 2 more | 2024-02-14 | 5.0 MEDIUM | N/A |
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow. | |||||
CVE-2006-5088 | 1 Phpheaven | 1 Phpmychat | 2024-02-14 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ChatPath parameter. | |||||
CVE-2007-2378 | 1 Google | 1 Web Toolkit | 2024-02-14 | 5.0 MEDIUM | N/A |
The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | |||||
CVE-2005-1328 | 1 Oneworldstore | 1 Oneworldstore | 2024-02-14 | 5.0 MEDIUM | N/A |
OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp. | |||||
CVE-2002-2117 | 1 Microsoft | 1 Windows Xp | 2024-02-14 | 5.0 MEDIUM | N/A |
Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP). | |||||
CVE-2005-1780 | 1 Dotnetindex | 1 Active News Manager | 2024-02-14 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. | |||||
CVE-2007-1654 | 1 Netsieben | 1 Netsieben Ssh Library | 2024-02-14 | 9.3 HIGH | N/A |
Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put and (2) get operations. | |||||
CVE-2005-3249 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer. | |||||
CVE-2002-1935 | 1 Pingtel | 1 Xpressa | 2024-02-14 | 5.0 MEDIUM | N/A |
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar. | |||||
CVE-2006-0578 | 1 Bluecoat | 1 Sgos | 2024-02-14 | 7.5 HIGH | N/A |
Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters. |