Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Support Center HIGH 7.5
CVE-2009-4541EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,950 2010-01-04
Facil Helpdesk MEDIUM 6.8
CVE-2009-4543

PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,600 2010-01-04
Freeschool HIGH 7.5
CVE-2009-4471

Multiple PHP remote file inclusion vulnerabilities in FreeSchool 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in …

Fix: after 1.1.0
Fix from $1,950 2009-12-30
Phpope HIGH 7.5
CVE-2009-4472

Multiple PHP remote file inclusion vulnerabilities in PHPope 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the …

Fix: after 1.0.0
Fix from $1,950 2009-12-30
Com Jcalpro HIGH 7.5
CVE-2009-4431

PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for …

No fix yet
Fix from $1,950 2009-12-28
Gpdf HIGH 9.3
CVE-2009-4035

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…

Mitigation only
Fix from $1,950 2009-12-21
Firefox HIGH 7.6
CVE-2009-3986

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Eocms MEDIUM 6.8
CVE-2009-4319

PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remot…

Fix: after 0.9.03
Fix from $1,600 2009-12-14
Windows 2000 HIGH 9.3
CVE-2009-4210EPSS 17%

The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corru…

Patch available
Fix from $1,950 2009-12-13
Windows 2000 HIGH 9.3
CVE-2009-4311EPSS 22%

Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute ar…

Patch available
Fix from $1,950 2009-12-13
Windows 2000 HIGH 9.3
CVE-2009-4312EPSS 21%

Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute ar…

Patch available
Fix from $1,950 2009-12-13
Adobe Air HIGH 9.3
CVE-2009-3796EPSS 7%

Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a…

Fix: after 10.0.32.18
Fix from $1,950 2009-12-10
Aroundme MEDIUM 6.8
CVE-2009-4264

PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote a…

Fix: after 1.1
Fix from $1,600 2009-12-10
Pointcomma HIGH 7.5
CVE-2009-4220

PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitra…

Fix: after 3.8b2
Fix from $1,950 2009-12-07
Kr Php Web Content Server HIGH 7.5
CVE-2009-4223EPSS 55%

PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a UR…

Fix: after 1.1
Fix from $1,950 2009-12-07
Daz Studio HIGH 9.3
CVE-2009-4148EPSS 5%

DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4)…

No fix yet
Fix from $1,950 2009-12-04
Wikipedia Toolbar HIGH 9.3
CVE-2009-4127

Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaSc…

Fix: after 0.5.9.1
Fix from $1,950 2009-12-02
Ciamos Cms HIGH 7.5
CVE-2009-4156

PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP cod…

Fix: after 0.9.5
Fix from $1,950 2009-12-02
Cutenews MEDIUM 6.5
CVE-2009-4113

Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users…

No fix yet
Fix from $1,600 2009-11-30
Cutenews MEDIUM 6.5
CVE-2009-4115

Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application a…

No fix yet
Fix from $1,600 2009-11-30
Mail MEDIUM 6.8
CVE-2009-4111

Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attacke…

No fix yet
Fix from $1,600 2009-11-29
Pear HIGH 7.5
CVE-2009-4023

Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allo…

Patch available
Fix from $1,950 2009-11-29
Pear HIGH 10.0
CVE-2009-4024EPSS 6%

Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute ar…

Fix: after 2.4.4
Fix from $1,950 2009-11-29
Outreach Project Tool HIGH 7.5
CVE-2009-4082

PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to…

Fix: after 1.2.7
Fix from $1,950 2009-11-29
Phptraverser HIGH 7.5
CVE-2009-4085

PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP c…

Mitigation only
Fix from $1,950 2009-11-29
Com Ezine HIGH 7.5
CVE-2009-4094

PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attack…

No fix yet
Fix from $1,950 2009-11-29
Autodesk Softimage HIGH 9.3
CVE-2009-3576

Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table…

No fix yet
Fix from $1,950 2009-11-24
3ds Max HIGH 9.3
CVE-2009-3577EPSS 5%

Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript …

No fix yet
Fix from $1,950 2009-11-24
Alias Wavefront Maya HIGH 9.3
CVE-2009-3578

Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (…

Mitigation only
Fix from $1,950 2009-11-24
WordPress MEDIUM 6.0
CVE-2009-3890EPSS 8%

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain confi…

Fix: after 2.8.5
Fix from $1,600 2009-11-17