Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Office Publisher HIGH 9.3
CVE-2009-0566EPSS 29%

Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2009-07-15
Isa Server HIGH 9.3
CVE-2009-1136EPSS 62%

The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP …

No fix yet
Fix from $1,950 2009-07-15
Directx HIGH 9.3
CVE-2009-1539EPSS 26%

The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and …

Mitigation only
Fix from $1,950 2009-07-15
Firefox HIGH 9.3
CVE-2009-2477EPSS 43%

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to ex…

Patch available
Fix from $1,950 2009-07-15
Mathtex HIGH 7.5
CVE-2009-1383

The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell…

Mitigation only
Fix from $1,950 2009-07-14
Edirectory MEDIUM 5.0
CVE-2009-2457

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP pack…

Patch available
Fix from $1,600 2009-07-14
Dm Album HIGH 9.3
CVE-2009-2396EPSS 6%

PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attacker…

No fix yet
Fix from $1,950 2009-07-09
Dm Filemanager MEDIUM 6.8
CVE-2009-2399

PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote atta…

No fix yet
Fix from $1,600 2009-07-09
Drupal MEDIUM 6.5
CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator…

Fix: 6.13+
Fix from $1,600 2009-07-08
Jax Formmailer HIGH 7.5
CVE-2009-2378

PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,950 2009-07-08
Windows 2003 Server HIGH 9.3
CVE-2008-0020EPSS 31%

Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video…

Patch available
Fix from $1,950 2009-07-07
Eaccelerator MEDIUM 6.8
CVE-2009-2353

encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a location under the web root via…

Mitigation only
Fix from $1,600 2009-07-07
Phpgreetcards MEDIUM 6.8
CVE-2008-6849

Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file wi…

No fix yet
Fix from $1,600 2009-07-07
Cms Chainuk HIGH 7.5
CVE-2009-2331

Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.p…

Fix: after 1.2
Fix from $1,950 2009-07-05
V Webmail MEDIUM 6.8
CVE-2008-6840

Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFI…

No fix yet
Fix from $1,600 2009-07-01
Com Dbquery HIGH 7.5
CVE-2008-6841EPSS 6%

PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 an…

Fix: after 1.4.1.1
Fix from $1,950 2009-07-01
Dedecms MEDIUM 6.8
CVE-2009-2270

Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a fil…

Mitigation only
Fix from $1,600 2009-07-01
Ajaxportal HIGH 7.5
CVE-2009-2262

PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pa…

Mitigation only
Fix from $1,950 2009-06-30
Phpcollegeexchange MEDIUM 6.8
CVE-2009-2218

Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute …

No fix yet
Fix from $1,600 2009-06-25
Campsite MEDIUM 6.8
CVE-2009-2182

Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBAL…

No fix yet
Fix from $1,600 2009-06-23
Pdf Viewer Component HIGH 9.3
CVE-2009-2169

Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows …

Fix: after 3.2.0
Fix from $1,950 2009-06-22
Firestats HIGH 7.5
CVE-2009-2143

PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers …

Fix: after 1.6.1
Fix from $1,950 2009-06-22
Db Top Sites HIGH 10.0
CVE-2009-2111

Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and…

No fix yet
Fix from $1,950 2009-06-18
Irfanview MEDIUM 6.8
CVE-2009-2118

Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a …

Patch available
Fix from $1,600 2009-06-18
Mundi Mail MEDIUM 6.8
CVE-2009-2095

PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allo…

No fix yet
Fix from $1,600 2009-06-17
Firefox HIGH 9.3
CVE-2009-1392EPSS 9%

The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1832EPSS 9%

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory c…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1833EPSS 9%

The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a d…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1838

The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's ow…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1841

js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote a…

Fix: after 3.0.10
Fix from $1,950 2009-06-12