Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
N5200pro Nas Server Control Panel MEDIUM 6.8
CVE-2008-0804

PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a …

No fix yet
Fix from $1,600 2008-02-19
Lan Manager HIGH 7.5
CVE-2008-0803EPSS 33%

Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2008-02-15
Joovili HIGH 10.0
CVE-2008-0743

PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a UR…

Fix: after 2.1
Fix from $1,950 2008-02-13
Office HIGH 10.0
CVE-2007-0065EPSS 43%

Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Of…

Mitigation only
Fix from $1,950 2008-02-12
Ie HIGH 9.3
CVE-2008-0076EPSS 29%

Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTM…

Mitigation only
Fix from $1,950 2008-02-12
Activex HIGH 9.3
CVE-2008-0078EPSS 29%

Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2008-02-12
Office HIGH 9.3
CVE-2008-0104EPSS 29%

Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub…

Mitigation only
Fix from $1,950 2008-02-12
Internet Information Server HIGH 10.0
CVE-2008-0075EPSS 57%

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via craf…

Mitigation only
Fix from $1,950 2008-02-12
Linux Kernel HIGH 7.2
CVE-2008-0600

The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows …

No fix yet
Fix from $1,950 2008-02-12
Mail MEDIUM 6.8
CVE-2008-0039

Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.

Patch available
Fix from $1,600 2008-02-12
Mac Os X MEDIUM 6.8
CVE-2008-0042

Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arb…

Patch available
Fix from $1,600 2008-02-12
Acrobat HIGH 9.3
CVE-2007-5663EPSS 13%

Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript…

Fix: after 8.1.1
Fix from $1,950 2008-02-12
Acrobat MEDIUM 6.2
CVE-2007-5666

Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Securi…

Fix: after 8.1.1
Fix from $1,600 2008-02-12
Clone Script HIGH 7.5
CVE-2008-0687

Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to i…

Mitigation only
Fix from $1,950 2008-02-12
Iphoto HIGH 9.3
CVE-2008-0043

Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.

Fix: after 7.1
Fix from $1,950 2008-02-08
Virtual Rooms HIGH 7.5
CVE-2008-0213

Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code vi…

Fix: after 6
Fix from $1,950 2008-02-07
Portail Web Php HIGH 7.5
CVE-2008-0645EPSS 34%

Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the s…

No fix yet
Fix from $1,950 2008-02-07
Opensiteadmin MEDIUM 6.8
CVE-2008-0648

Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a UR…

Fix: after 0.9.1.1
Fix from $1,600 2008-02-07
Openads HIGH 7.5
CVE-2008-0635EPSS 12%

Unspecified vulnerability in the delivery engine in Openads 2.4.0 through 2.4.2 allows remote attackers to execute arbitrary PHP code via unknown vec…

Patch available
Fix from $1,950 2008-02-06
Php Links MEDIUM 6.8
CVE-2008-0566EPSS 23%

PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,600 2008-02-05
Chronoforms HIGH 7.5
CVE-2008-0567EPSS 34%

Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers…

No fix yet
Fix from $1,950 2008-02-05
Mindmeld MEDIUM 6.8
CVE-2008-0572EPSS 22%

Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOB…

No fix yet
Fix from $1,600 2008-02-05
Cforms MEDIUM 6.8
CVE-2008-0560

PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to exec…

Mitigation only
Fix from $1,600 2008-02-04
Activex HIGH 9.3
CVE-2008-0551EPSS 30%

The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows rem…

No fix yet
Fix from $1,950 2008-02-01
Connectix Boards HIGH 7.5
CVE-2008-0502

PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to e…

Fix: after 0.8.2
Fix from $1,950 2008-01-31
Smart Publisher MEDIUM 6.8
CVE-2008-0503EPSS 23%

Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the file…

No fix yet
Fix from $1,600 2008-01-31
Sqlite Manager HIGH 9.3
CVE-2008-0516

PHP remote file inclusion vulnerability in spaw/dialogs/confirm.php in SQLiteManager 1.2.0 allows remote attackers to execute arbitrary PHP code via …

Mitigation only
Fix from $1,950 2008-01-31
Weblog HIGH 7.5
CVE-2008-0442

PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL …

No fix yet
Fix from $1,950 2008-01-25
Phpsearch HIGH 7.5
CVE-2008-0448

PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL…

Mitigation only
Fix from $1,950 2008-01-25
Blog Cms HIGH 7.5
CVE-2008-0450

Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_…

Mitigation only
Fix from $1,950 2008-01-25