Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Fsphp HIGH 7.5
CVE-2009-3307

Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB par…

No fix yet
Fix from $1,950 2009-09-23
Phppollscript MEDIUM 6.8
CVE-2009-3312

PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attack…

Fix: after 1.3
Fix from $1,600 2009-09-23
Opensiteadmin HIGH 7.5
CVE-2009-3317

PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,950 2009-09-23
Barosmini HIGH 7.5
CVE-2009-3323

Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,950 2009-09-23
Prodler HIGH 7.5
CVE-2009-3324

PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code…

Fix: after 2.0
Fix from $1,950 2009-09-23
Ddl Cms HIGH 7.5
CVE-2009-3331

Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot param…

No fix yet
Fix from $1,950 2009-09-23
Com Koesubmit HIGH 7.5
CVE-2009-3333

PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute …

No fix yet
Fix from $1,950 2009-09-23
Clearsite HIGH 7.5
CVE-2009-3306EPSS 6%

PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2009-09-23
Php User Base HIGH 7.5
CVE-2008-7240EPSS 6%

Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and …

No fix yet
Fix from $1,950 2009-09-17
Aiocp HIGH 7.5
CVE-2009-3220

PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2009-09-16
Phpsane HIGH 7.5
CVE-2009-3188EPSS 6%

PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save…

No fix yet
Fix from $1,950 2009-09-15
Mac Os X MEDIUM 6.8
CVE-2009-2809

ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2811

Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a …

Patch available
Fix from $1,600 2009-09-14
Extended Module Player HIGH 10.0
CVE-2007-6731EPSS 14%

Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses…

Fix: after 2.5.1
Fix from $1,950 2009-09-13
Obophix HIGH 7.5
CVE-2009-3174

PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code vi…

Fix: after 2.7.0
Fix from $1,950 2009-09-11
Firefox HIGH 9.3
CVE-2009-3077

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, whi…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3079

Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chro…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Lotus Notes HIGH 7.5
CVE-2009-3114

The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2009-09-09
Eva Cms MEDIUM 6.8
CVE-2008-7183

PHP remote file inclusion vulnerability in eva/index.php in EVA CMS 2.3.1, when register_globals is enabled, allows remote attackers to execute arbit…

No fix yet
Fix from $1,600 2009-09-08
Windows Media Format Runtime HIGH 9.3
CVE-2009-2498EPSS 21%

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced S…

Mitigation only
Fix from $1,950 2009-09-08
Windows Media Format Runtime HIGH 8.5
CVE-2009-2499EPSS 16%

Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows r…

Mitigation only
Fix from $1,950 2009-09-08
Ace HIGH 9.3
CVE-2009-2628EPSS 6%

The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player…

Patch available
Fix from $1,950 2009-09-08
Vedit HIGH 7.5
CVE-2009-3065

PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL …

No fix yet
Fix from $1,950 2009-09-03
Kingcms HIGH 7.5
CVE-2009-3056

PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2009-09-03
Dle HIGH 7.5
CVE-2009-3055

PHP remote file inclusion vulnerability in engine/api/api.class.php in DataLife Engine (DLE) 8.2 allows remote attackers to execute arbitrary PHP cod…

No fix yet
Fix from $1,950 2009-09-03
Sid MEDIUM 6.8
CVE-2008-7152

Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to exec…

No fix yet
Fix from $1,600 2009-09-01
Zkup MEDIUM 6.8
CVE-2008-7123

Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP c…

Patch available
Fix from $1,600 2009-08-31
Openpro HIGH 7.5
CVE-2008-7087

PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBP…

No fix yet
Fix from $1,950 2009-08-26
Page Tree Cms HIGH 7.5
CVE-2008-7067

PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2009-08-25
Kvirc HIGH 9.3
CVE-2008-7070EPSS 5%

Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) follow…

No fix yet
Fix from $1,950 2009-08-25