CVE-2011-5279
|
CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.
Published:
April 23, 2014; 04:55:06 PM -04:00
|
V2: 6.4 MEDIUM
|
CVE-2008-5232
|
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published:
November 25, 2008; 08:30:00 PM -05:00
|
V2: 9.3 HIGH
|
CVE-2008-4609
|
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
Published:
October 20, 2008; 01:59:26 PM -04:00
|
V2: 7.1 HIGH
|
CVE-2008-3860
|
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.
Published:
August 29, 2008; 12:41:00 PM -04:00
|
V2: 4.3 MEDIUM
|
CVE-2008-2430
|
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
Published:
July 07, 2008; 07:41:00 PM -04:00
|
V2: 9.3 HIGH
|
CVE-2008-2427
|
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.
Published:
June 24, 2008; 03:41:00 PM -04:00
|
V2: 9.3 HIGH
|
CVE-2008-2841
|
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
Published:
June 24, 2008; 03:41:00 PM -04:00
|
V2: 6.8 MEDIUM
|
CVE-2008-2821
|
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
Published:
June 23, 2008; 01:41:00 PM -04:00
|
V2: 9.3 HIGH
|
CVE-2008-2674
|
Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors.
Published:
June 12, 2008; 08:21:00 AM -04:00
|
V2: 6.4 MEDIUM
|
CVE-2008-2163
|
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Published:
May 13, 2008; 01:20:00 PM -04:00
|
V2: 4.3 MEDIUM
|
CVE-2007-6423
|
** DISPUTED ** Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue.
Published:
January 11, 2008; 07:46:00 PM -05:00
|
V2: 7.8 HIGH
|
CVE-2007-6334
|
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
Published:
December 20, 2007; 06:46:00 PM -05:00
|
V2: 5.0 MEDIUM
|
CVE-2007-6026
|
Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
Published:
November 19, 2007; 07:46:00 PM -05:00
|
V2: 9.3 HIGH
|
CVE-2007-4938
|
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
Published:
September 18, 2007; 03:17:00 PM -04:00
|
V2: 7.6 HIGH
|
CVE-2007-3958
|
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.
Published:
July 24, 2007; 02:30:00 PM -04:00
|
V2: 7.1 HIGH
|
CVE-2007-2736
|
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
Published:
May 17, 2007; 03:30:00 PM -04:00
|
V2: 10.0 HIGH
|
CVE-2007-1898
|
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
Published:
May 16, 2007; 06:30:00 PM -04:00
|
V2: 5.8 MEDIUM
|
CVE-2007-2186
|
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
Published:
April 24, 2007; 01:19:00 PM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2007-1973
|
Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.
Published:
April 11, 2007; 07:19:00 PM -04:00
|
V2: 6.9 MEDIUM
|
CVE-2007-1912
|
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.
Published:
April 10, 2007; 07:19:00 PM -04:00
|
V2: 6.8 MEDIUM
|