Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2009-4541EPSS 8% Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in t… Support Center No fix yet Fix from $1,9502010-01-04 MEDIUM 6.8 CVE-2009-4543 PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary P… Facil Helpdesk No fix yet Fix from $1,6002010-01-04 HIGH 7.5 CVE-2009-4471 Multiple PHP remote file inclusion vulnerabilities in FreeSchool 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in … Freeschool after 1.1.0 Fix from $1,9502009-12-30 HIGH 7.5 CVE-2009-4472 Multiple PHP remote file inclusion vulnerabilities in PHPope 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the … Phpope after 1.0.0 Fix from $1,9502009-12-30 HIGH 7.5 CVE-2009-4431 PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for … Com Jcalpro No fix yet Fix from $1,9502009-12-28 HIGH 9.3 CVE-2009-4035 The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d… Gpdf Mitigation only Fix from $1,9502009-12-21 HIGH 7.6 CVE-2009-3986 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome… Firefox after 3.0.15 Fix from $1,9502009-12-17 MEDIUM 6.8 CVE-2009-4319 PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remot… Eocms after 0.9.03 Fix from $1,6002009-12-14 HIGH 9.3 CVE-2009-4210EPSS 17% The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corru… Windows 2000 Patch available Fix from $1,9502009-12-13 HIGH 9.3 CVE-2009-4311EPSS 22% Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute ar… Windows 2000 Patch available Fix from $1,9502009-12-13 HIGH 9.3 CVE-2009-4312EPSS 21% Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute ar… Windows 2000 Patch available Fix from $1,9502009-12-13 HIGH 9.3 CVE-2009-3796EPSS 7% Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a… Adobe Air after 10.0.32.18 Fix from $1,9502009-12-10 MEDIUM 6.8 CVE-2009-4264 PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote a… Aroundme after 1.1 Fix from $1,6002009-12-10 HIGH 7.5 CVE-2009-4220 PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitra… Pointcomma after 3.8b2 Fix from $1,9502009-12-07 HIGH 7.5 CVE-2009-4223EPSS 55% PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a UR… Kr Php Web Content Server after 1.1 Fix from $1,9502009-12-07 HIGH 9.3 CVE-2009-4148EPSS 5% DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4)… Daz Studio No fix yet Fix from $1,9502009-12-04 HIGH 9.3 CVE-2009-4127 Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaSc… Wikipedia Toolbar after 0.5.9.1 Fix from $1,9502009-12-02 HIGH 7.5 CVE-2009-4156 PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP cod… Ciamos Cms after 0.9.5 Fix from $1,9502009-12-02 MEDIUM 6.5 CVE-2009-4113 Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users… Cutenews No fix yet Fix from $1,6002009-11-30 MEDIUM 6.5 CVE-2009-4115 Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application a… Cutenews No fix yet Fix from $1,6002009-11-30 MEDIUM 6.8 CVE-2009-4111 Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attacke… Mail No fix yet Fix from $1,6002009-11-29 HIGH 7.5 CVE-2009-4023 Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allo… Pear Patch available Fix from $1,9502009-11-29 HIGH 10.0 CVE-2009-4024EPSS 6% Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute ar… Pear after 2.4.4 Fix from $1,9502009-11-29 HIGH 7.5 CVE-2009-4082 PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to… Outreach Project Tool after 1.2.7 Fix from $1,9502009-11-29 HIGH 7.5 CVE-2009-4085 PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP c… Phptraverser Mitigation only Fix from $1,9502009-11-29 HIGH 7.5 CVE-2009-4094 PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attack… Com Ezine No fix yet Fix from $1,9502009-11-29 HIGH 9.3 CVE-2009-3576 Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table… Autodesk Softimage No fix yet Fix from $1,9502009-11-24 HIGH 9.3 CVE-2009-3577EPSS 5% Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript … 3ds Max No fix yet Fix from $1,9502009-11-24 HIGH 9.3 CVE-2009-3578 Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (… Alias Wavefront Maya Mitigation only Fix from $1,9502009-11-24 MEDIUM 6.0 CVE-2009-3890EPSS 8% Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain confi… WordPress after 2.8.5 Fix from $1,6002009-11-17