Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Doomsday HIGH 7.5
CVE-2007-4644

Format string vulnerability in the Cl_GetPackets function in cl_main.c in the client in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote D…

Fix: after 1.9.0_beta5.1
Fix from $1,950 2007-08-31
Nmdeluxe MEDIUM 6.4
CVE-2007-4645

SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspo…

No fix yet
Fix from $1,600 2007-08-31
Hexamail Server HIGH 10.0
CVE-2007-4646EPSS 16%

Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probabl…

No fix yet
Fix from $1,950 2007-08-31
Virtual War HIGH 7.5
CVE-2007-4605

PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary …

Fix: after 1.5.0_r15
Fix from $1,950 2007-08-31
Phpnuke Clan HIGH 7.5
CVE-2007-4606

PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows r…

Fix: after 4.2.0
Fix from $1,950 2007-08-31
Epersonnel HIGH 7.5
CVE-2007-4608

PHP remote file inclusion vulnerability in protection.php in ePersonnel RC_2004_02 allows remote attackers to execute arbitrary PHP code via a URL in…

Mitigation only
Fix from $1,950 2007-08-31
PHP HIGH 7.5
CVE-2007-4596EPSS 8%

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva…

No fix yet
Fix from $1,950 2007-08-30
Arcadem HIGH 7.5
CVE-2007-4551

PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in …

Patch available
Fix from $1,950 2007-08-28
Spip HIGH 7.5
CVE-2007-4525

PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squel…

Mitigation only
Fix from $1,950 2007-08-25
Firesoft HIGH 7.5
CVE-2007-4458

PHP remote file inclusion vulnerability in includes/class/class_tpl.php in Firesoft allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2007-08-21
Poll Script HIGH 7.5
CVE-2007-4339

Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in th…

Mitigation only
Fix from $1,950 2007-08-14
Login HIGH 7.5
CVE-2007-4342

PHP remote file inclusion vulnerability in include.php in PHPCentral Login 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the…

No fix yet
Fix from $1,950 2007-08-14
Bilder Galerie MEDIUM 6.8
CVE-2007-4328EPSS 6%

Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,600 2007-08-14
Guestbook Script CRITICAL 9.8
CVE-2007-4290

Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary PHP code via a URL in the scri…

Mitigation only
Fix from $2,300 2007-08-09
J Reactions HIGH 7.5
CVE-2007-4244EPSS 8%

PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attacke…

Fix: after 1.8.1
Fix from $1,950 2007-08-08
Joomla HIGH 7.5
CVE-2007-4187EPSS 11%

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-08-08
Vgallite HIGH 7.5
CVE-2007-4169

Multiple PHP remote file inclusion vulnerabilities in vgallite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dirpath para…

No fix yet
Fix from $1,950 2007-08-07
Confixx HIGH 9.3
CVE-2007-4009

PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to ex…

No fix yet
Fix from $1,950 2007-07-26
Generic Youtube Clone Script HIGH 9.3
CVE-2007-3773

Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files …

Mitigation only
Fix from $1,950 2007-07-15
Mycms HIGH 7.5
CVE-2007-3586

Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _scor…

Fix: after 0.9.8
Fix from $1,950 2007-07-05
Ie HIGH 7.8
CVE-2007-3550EPSS 28%

Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards v…

Patch available
Fix from $1,950 2007-07-03
Jd Wiki MEDIUM 6.8
CVE-2007-3130

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla…

No fix yet
Fix from $1,600 2007-06-08
Firefox HIGH 9.3
CVE-2007-2868

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12…

Mitigation only
Fix from $1,950 2007-06-01
Navboard HIGH 7.5
CVE-2007-2899

Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/confi…

No fix yet
Fix from $1,950 2007-05-30
Scallywag MEDIUM 6.8
CVE-2007-2900

Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path…

No fix yet
Fix from $1,600 2007-05-30
Ol Bookmarks HIGH 7.5
CVE-2007-2816EPSS 10%

Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root p…

No fix yet
Fix from $1,950 2007-05-22
Madirish Webmail HIGH 7.5
CVE-2007-2826

PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2007-05-22
Norton Antivirus HIGH 8.5
CVE-2006-3456

The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and Sy…

Mitigation only
Fix from $1,950 2007-05-11
Gnu Edu HIGH 7.5
CVE-2007-2609EPSS 10%

Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code via a URL in the (a) ETCDIR p…

No fix yet
Fix from $1,950 2007-05-11
Noah HIGH 7.5
CVE-2007-2572

PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earl…

Fix: after 0.9_pre_1.2
Fix from $1,950 2007-05-09