| back IPureServer -- S.T.A.L.K.E.R. |
Stack-based buffer overflow in the IPureServer:: Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET Compressor::Decompress function. | 2009-04-10 | 10.0 | CVE-2008-6703 XF BUGTRAQ SECUNIA OSVDB MISC
|
back acutecp -- acute control panel
|
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme directory parameter to (1) container.php and (2) header.php in themes/. | 2009-04-06 | 7.5 | CVE-2009-1248 XF BID MILW0RM SECUNIA
|
back acutecp.rediscussed -- acutecp
|
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2009-1247 XF BID MILW0RM SECUNIA
|
back beaussier -- roomphplanning
|
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php. | 2009-04-07 | 7.5 | CVE-2008-6633 XF VUPEN BID MILW0RM SECUNIA
|
back beaussier -- roomphplanning
|
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php. | 2009-04-07 | 7.5 | CVE-2008-6634 XF BID MILW0RM SECUNIA
|
back cclamav -- clamav clamav -- clamav clamavclamav -- 0.11 clamavclamav -- 0.80 rc4 clamavs -- clamav
|
libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted file that causes (1) clamd and (2) clamscan to hang. | 2009-04-08 | 7.8 | CVE-2009-1270 CONFIRM MLIST
|
back cisco -- adaptive security appliance 5500 cisco -- pix
|
Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors. | 2009-04-09 | 7.8 | CVE-2009-1155 CISCO
|
back cisco -- adaptive security appliance 5500 cisco -- pix
|
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet. | 2009-04-09 | 7.8 | CVE-2009-1157 CISCO
|
back cisco -- adaptive security appliance 5500 cisco -- pix
|
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)26, 8.0 before 8.0(4)24, and 8.1 before 8.1(2)14, when H.323 inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet. | 2009-04-09 | 7.8 | CVE-2009-1158 CISCO
|
back cisco -- adaptive security appliance 5500 cisco -- pix
|
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before 7.2(4)26, 8.0 before 8.0(4)22, and 8.1 before 8.1(2)12, when SQL*Net inspection is enabled, allows remote attackers to cause a denial of service (traceback and device reload) via a series of SQL*Net packets. | 2009-04-09 | 7.8 | CVE-2009-1159 CISCO
|
back clam anti-virus -- clamav clamav -- clamav
|
Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive. | 2009-04-03 | 7.5 | CVE-2009-1241 BID BUGTRAQ MLIST MISC
|
back class-systems -- class systems
|
Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/. | 2009-04-06 | 7.5 | CVE-2008-6619 XF VUPEN BID BUGTRAQ MISC SECUNIA
|
back diocese of portsmouth -- pd calendar today typo3 -- typo3
|
SQL injection vulnerability in Diocese of Portsmouth Calendar Today (pd calendar today) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6691 CONFIRM
|
back dirk bartley -- nweb2fax
|
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var filename parameter in a (1) tif or (2) pdf format action. | 2009-04-08 | 7.5 | CVE-2008-6669 XF BID MILW0RM
|
back dotcontent -- fluentcms
|
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter. NOTE: some of these details are obtained from third party information. | 2009-04-07 | 7.5 | CVE-2008-6642 XF BID MILW0RM SECUNIA
|
back ezbsystems -- ultraiso
|
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file. | 2009-04-07 | 9.0 | CVE-2009-1260 XF VUPEN MILW0RM SECUNIA OSVDB
|
back flexcms -- flexcms
|
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. NOTE: some of these details are obtained from third party information. | 2009-04-07 | 7.5 | CVE-2009-1256 XF BID MILW0RM
|
back fortinet -- forticlient
|
Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name. | 2009-04-07 | 7.2 | CVE-2009-1262 XF VUPEN SECTRACK BUGTRAQ MISC SECUNIA OSVDB FULLDISC
|
back fr.simon rundell -- pd trainingcourses
|
SQL injection vulnerability in Diocese of Portsmouth Training Courses (pd trainingcourses) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6692 CONFIRM
|
back fr.simon rundell -- ste prayer
|
SQL injection vulnerability in Random Prayer (ste prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6694 CONFIRM
|
back frank naegler -- timtab sociable
|
SQL injection vulnerability in TIMTAB social bookmark icons (timtab sociable) 2.0.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6695 CONFIRM
|
back geody -- dagger
|
SQL injection vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register globals is enabled, allows remote attackers to execute arbitrary SQL commands via the dir inc parameter. | 2009-04-07 | 7.5 | CVE-2008-6635 BID MILW0RM SECUNIA
|
back ghostscript -- ghostscript
|
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf decode 2d function. | 2009-04-08 | 7.5 | CVE-2007-6725 CONFIRM CONFIRM MLIST FEDORA
|
back glfusion -- glfusion
|
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf session cookie parameter. | 2009-04-09 | 7.5 | CVE-2009-1282 BID CONFIRM
|
back graphicsmagick -- graphicsmagick
|
Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information. | 2009-04-06 | 7.8 | CVE-2008-6621 VUPEN CONFIRM SECUNIA CONFIRM
|
back gravityboardx -- gravity board x
|
SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member id parameter in a viewprofile action. NOTE: the board id issue is already covered by CVE-2008-2996.2. | 2009-04-09 | 7.5 | CVE-2009-1277 XF BID MILW0RM
|
back gravityboardx -- gravity board x
|
Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php. | 2009-04-09 | 7.5 | CVE-2009-1278 XF BID MILW0RM
|
back impliedbydesign -- ibd micro cms
|
Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | 2009-04-06 | 7.5 | CVE-2008-6614 XF MISC BID MISC
|
back insanevisions -- onecms
|
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter. | 2009-04-07 | 7.5 | CVE-2008-6652 XF BID MILW0RM
|
back irfanview -- formats
|
Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow. | 2009-04-09 | 9.3 | CVE-2009-0197 XF VUPEN CONFIRM
|
back janbednarik -- cooluri typo3 -- typo3
|
SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6686 CONFIRM
|
back joomla -- joomla rd-media -- rd-autos
|
SQL injection vulnerability in the RD-Autos (com rdautos) component 1.5.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the makeid parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-04-07 | 7.5 | CVE-2009-1258 XF BID SECUNIA OSVDB
|
back kevin renskers -- dmmjobcontrol
|
SQL injection vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6689 CONFIRM
|
back ktools -- photostore
|
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter. | 2009-04-07 | 7.5 | CVE-2008-6647 XF BID MILW0RM SECUNIA
|
back ktools -- photostore
|
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about us.php. NOTE: this might be the same issue as CVE-2008-6647. | 2009-04-07 | 7.5 | CVE-2008-6648 XF BID MILW0RM SECUNIA
|
back ktools -- photostore
|
SQL injection vulnerability in manager/image details editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2009-04-07 | 7.5 | CVE-2008-6649 XF BID MILW0RM SECUNIA
|
back linux -- linux openafs -- openafs
|
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR PTR macro. | 2009-04-08 | 7.8 | CVE-2009-1250 BID CONFIRM CONFIRM
|
back magic iso maker -- magic iso maker
|
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file. | 2009-04-07 | 9.0 | CVE-2009-1257 XF VUPEN MILW0RM SECUNIA OSVDB
|
back manu oehler -- toto typo3 -- typo3
|
SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6696 CONFIRM
|
back marc melvin -- a php scripts news management system
|
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | 2009-04-08 | 7.5 | CVE-2008-6667 BID MILW0RM
|
back mercuryboard -- mercuryboard
|
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($ SERVER['HTTP USER AGENT']). | 2009-04-07 | 7.5 | CVE-2008-6632 XF BID MILW0RM
|
back michael fritz -- worldcup
|
SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6697 CONFIRM
|
back mit -- kerberos
|
The asn1 decode generaltime function in lib/krb5/asn.1/asn1 decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. | 2009-04-08 | 10.0 | CVE-2009-0846 CONFIRM
|
back netlab -- classsystem
|
Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message id parameter in class/MessageReply.php. | 2009-04-06 | 7.5 | CVE-2008-6618 XF VUPEN BID BUGTRAQ MISC SECUNIA
|
back netscout -- ngenius infinistream netscout -- visualizer
|
NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en US/domains/add domain.jsp, which allows remote attackers to gain administrator privileges via a direct request. | 2009-04-10 | 7.5 | CVE-2008-6701 XF BUGTRAQ SECUNIA OSVDB
|
back nikola arezina -- com bookjoomlas
|
SQL injection vulnerability in sub commententry.php in the BookJoomlas (com bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php. | 2009-04-07 | 7.5 | CVE-2009-1263 XF VUPEN BID MILW0RM
|
back openafs -- openafs unix -- unix
|
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays. | 2009-04-08 | 10.0 | CVE-2009-1251 CONFIRM
|
back openautoclassifieds -- open auto classifieds
|
Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php. | 2009-04-07 | 7.5 | CVE-2008-6656 XF BID MILW0RM
|
back oxyproject -- oxybox
|
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. | 2009-04-07 | 10.0 | CVE-2008-6651 XF BID MILW0RM
|
back phpauctions -- phpauction
|
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction id parameter, a different vector than CVE-2009-0106. | 2009-04-08 | 7.5 | CVE-2008-6663 XF BID MILW0RM
|
back quickersite -- quickersite
|
Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | 2009-04-08 | 7.5 | CVE-2008-6677 MISC MISC SECUNIA
|
back quickersite -- quickersite
|
SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp. | 2009-04-08 | 7.5 | CVE-2008-6678 MISC MISC SECUNIA
|
back sebastian baumann -- sb downloader typo3 -- typo3
|
SQL injection vulnerability in Download system (sb downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6693 CONFIRM
|
back thomas waggershauser -- air filemanager
|
Unspecified vulnerability in Frontend Filemanager (air filemanager) 0.6.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary commands via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6685 CONFIRM
|
back typo3 -- nd antispam
|
Unspecified vulnerability in nepa-design.de Spam Protection (nd antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors. | 2009-04-10 | 7.5 | CVE-2008-6690 CONFIRM
|
back versalsoft -- http file upload activex control
|
Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method. | 2009-04-07 | 8.8 | CVE-2008-6638 XF BID MILW0RM
|
back vertex4 -- sunage
|
Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted join packet to UDP port 27960. | 2009-04-08 | 7.8 | CVE-2008-6671 XF VUPEN BID SECUNIA OSVDB MISC MISC
|
back vmware -- ace vmware -- player vmware -- server vmware -- workstation
|
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CVE-435. | 2009-04-06 | 9.3 | CVE-2009-0909 FULLDISC MLIST
|
back webbdomain -- post card
|
SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2008-6623 XF BID MILW0RM SECUNIA OSVDB
|
back webbdomain -- petition
|
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2008-6624 XF BID MILW0RM OSVDB
|
back webbdomain -- polls
|
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2008-6625 XF BID MILW0RM SECUNIA OSVDB
|
back webbdomain -- quiz
|
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2008-6626 XF BID MILW0RM SECUNIA OSVDB
|
back webbdomain -- web shop
|
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2009-04-06 | 7.5 | CVE-2008-6627 XF BID MILW0RM SECUNIA OSVDB
|
back webbdomain -- web shop online
|
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2009-04-06 | 7.5 | CVE-2008-6628 MILW0RM SECUNIA OSVDB
|
back webbdomian -- post card
|
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | 2009-04-06 | 7.5 | CVE-2008-6622 BID MILW0RM SECUNIA OSVDB
|
back wh-com -- com webhosting
|
SQL injection vulnerability in webhosting.php in the Webhosting Component (com webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | 2009-04-07 | 7.5 | CVE-2008-6653 XF BID MILW0RM CONFIRM
|
back yarck -- sh-news
|
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values. | 2009-04-08 | 7.5 | CVE-2008-6664 XF MISC BID MILW0RM
|
back zen-cart -- zen cart
|
SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the advanced search result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-04-06 | 7.5 | CVE-2008-6615 XF BID MISC
|