CVE-database
78.857 CVEs in database. Zoek op product (bv. fortinet, exchange) of CVE-ID.
- CVE-2014-2235 MEDIUM · 4.3 Cross-site scripting (XSS) -kwetsbaarheid in Askbot vóór 0.7.49 stelt externe aanvallers in staat om willekeurig webscript of HTML te injecteren via vectoren die verband houden… Askbot
- CVE-2014-2206 HIGH · 10.0 Op stapels gebaseerde bufferoverloop in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502 en eerder stelt externe aanvallers in staat om een denial of service (crash) te… Getgosoft
- CVE-2013-3478 HIGH · 7.5 SQL-injectiekwetsbaarheid in Apptha WordPress Video Gallery 2.0, 1.6 en eerder voor WordPress stelt externe aanvallers in staat om willekeurige SQL-opdrachten uit te voeren via de… Apptha
- CVE-2014-0759 MEDIUM · 5.9 Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application… Schneider-electric
- CVE-2011-4327 MEDIUM · 5.5 ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key… Openbsd
- CVE-2014-1692 HIGH · 7.3 The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which… Openbsd
- CVE-2013-4734 HIGH · 7.3 dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which… Digital Alert Systems Monroe Electronics
- CVE-2013-4733 HIGH · 7.5 The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote… Digital Alert Systems Monroe Electronics
- CVE-2013-0270 MEDIUM · 6.5 A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long… Openstack
- CVE-2013-1609 MEDIUM · 6.8 Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving… Symantec
- CVE-2013-0335 HIGH · 7.6 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the… Openstack Canonical
- CVE-2013-2566 MEDIUM · 5.9 The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct… Oracle Fujitsu Canonical Mozilla
- CVE-2010-5107 HIGH · 7.5 The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier… Openbsd
- CVE-2012-6442 HIGH · 7.5 When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP… Rockwellautomation
- CVE-2012-6440 MEDIUM · 4.8 The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow… Rockwellautomation
- CVE-2012-6438 HIGH · 7.5 The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port… Rockwellautomation
- CVE-2012-6437 CRITICAL · 9.8 The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card,… Rockwellautomation
- CVE-2012-6436 HIGH · 7.5 The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port… Rockwellautomation
- CVE-2012-6435 HIGH · 7.5 When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP… Rockwellautomation
- CVE-2012-4550 MEDIUM · 5.3 A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly… Redhat
- CVE-2012-4549 MEDIUM · 6.5 A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined… Redhat
- CVE-2011-4045 MEDIUM · 4.3 Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a… Arcinfo
- CVE-2011-4044 MEDIUM · 5.8 An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to… Arcinfo
- CVE-2011-4043 HIGH · 9.3 Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary… Arcinfo
- CVE-2011-4042 HIGH · 9.3 An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using… Arcinfo
- CVE-2012-0814 LOW · 3.5 The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain… Openbsd
- CVE-2011-0539 HIGH · 7.5 The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the… Openbsd
- CVE-2010-4634 MEDIUM · 5.0 Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a… Enhancesoft
- CVE-2010-4478 CRITICAL · 9.8 OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass… Openbsd
- CVE-2010-3190 HIGH · 7.8 Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and… Apple Microsoft
- CVE-2010-2965 CRITICAL · 9.8 The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware… Rockwellautomation Windriver
- CVE-2010-0606 LOW · 3.5 Cross-site scripting (XSS) kwetsbaarheid in scp/ajax.php in osTicket voor 1.6.0 Stabiel stelt op afstand geverifieerde gebruikers in staat om willekeurig webscript of HTML te injecteren… Enhancesoft Osticket
- CVE-2010-0605 HIGH · 7.5 SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input… Enhancesoft Osticket
- CVE-2010-0386 HIGH · 8.1 The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers… Sun
- CVE-2009-3555 CRITICAL · 9.8 The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP… Apache Gnu Mozilla Openssl
- CVE-2009-3720 MEDIUM · 5.0 The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a… Libexpat Project Python Apache
- CVE-2009-2495 MEDIUM · 6.5 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005… Microsoft
- CVE-2009-2493 HIGH · 8.8 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005… Microsoft
- CVE-2009-0901 HIGH · 8.8 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and… Microsoft
- CVE-2009-2361 HIGH · 7.5 SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter. Enhancesoft
- CVE-2003-1567 HIGH · 7.5 The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which… Microsoft
- CVE-2004-2761 CRITICAL · 9.8 The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the… Ietf
- CVE-2008-5161 LOW · 3.7 Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8;… Openbsd Ssh
- CVE-2008-4309 HIGH · 7.5 Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause… Net-snmp
- CVE-2006-5407 HIGH · 7.5 PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. Enhancesoft
- CVE-2005-4459 HIGH · 10.0 Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote… Vmware
- CVE-2005-2096 HIGH · 7.5 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description… Zlib
- CVE-2005-1794 MEDIUM · 6.4 Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows… Microsoft
- CVE-2005-1439 HIGH · 7.5 Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter. Enhancesoft
- CVE-2005-1436 MEDIUM · 6.8 Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2)… Enhancesoft