Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 9.3 CVE-2009-0566EPSS 29% Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arb… Office Publisher Mitigation only Fix from $1,9502009-07-15 HIGH 9.3 CVE-2009-1136EPSS 62% The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP … Isa Server No fix yet Fix from $1,9502009-07-15 HIGH 9.3 CVE-2009-1539EPSS 26% The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and … Directx Mitigation only Fix from $1,9502009-07-15 HIGH 9.3 CVE-2009-2477EPSS 43% js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to ex… Firefox Patch available Fix from $1,9502009-07-15 HIGH 7.5 CVE-2009-1383 The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell… Mathtex Mitigation only Fix from $1,9502009-07-14 MEDIUM 5.0 CVE-2009-2457 The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP pack… Edirectory Patch available Fix from $1,6002009-07-14 HIGH 9.3 CVE-2009-2396EPSS 6% PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attacker… Dm Album No fix yet Fix from $1,9502009-07-09 MEDIUM 6.8 CVE-2009-2399 PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote atta… Dm Filemanager No fix yet Fix from $1,6002009-07-09 MEDIUM 6.5 CVE-2009-2372 Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator… Drupal 6.13+ Fix from $1,6002009-07-08 HIGH 7.5 CVE-2009-2378 PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via… Jax Formmailer No fix yet Fix from $1,9502009-07-08 HIGH 9.3 CVE-2008-0020EPSS 31% Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video… Windows 2003 Server Patch available Fix from $1,9502009-07-07 MEDIUM 6.8 CVE-2009-2353 encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a location under the web root via… Eaccelerator Mitigation only Fix from $1,6002009-07-07 MEDIUM 6.8 CVE-2008-6849 Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file wi… Phpgreetcards No fix yet Fix from $1,6002009-07-07 HIGH 7.5 CVE-2009-2331 Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary PHP code (1) into settings.p… Cms Chainuk after 1.2 Fix from $1,9502009-07-05 MEDIUM 6.8 CVE-2008-6840 Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFI… V Webmail No fix yet Fix from $1,6002009-07-01 HIGH 7.5 CVE-2008-6841EPSS 6% PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 an… Com Dbquery after 1.4.1.1 Fix from $1,9502009-07-01 MEDIUM 6.8 CVE-2009-2270 Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a fil… Dedecms Mitigation only Fix from $1,6002009-07-01 HIGH 7.5 CVE-2009-2262 PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pa… Ajaxportal Mitigation only Fix from $1,9502009-06-30 MEDIUM 6.8 CVE-2009-2218 Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute … Phpcollegeexchange No fix yet Fix from $1,6002009-06-25 MEDIUM 6.8 CVE-2009-2182 Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBAL… Campsite No fix yet Fix from $1,6002009-06-23 HIGH 9.3 CVE-2009-2169 Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows … Pdf Viewer Component after 3.2.0 Fix from $1,9502009-06-22 HIGH 7.5 CVE-2009-2143 PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers … Firestats after 1.6.1 Fix from $1,9502009-06-22 HIGH 10.0 CVE-2009-2111 Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and… Db Top Sites No fix yet Fix from $1,9502009-06-18 MEDIUM 6.8 CVE-2009-2118 Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a … Irfanview Patch available Fix from $1,6002009-06-18 MEDIUM 6.8 CVE-2009-2095 PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allo… Mundi Mail No fix yet Fix from $1,6002009-06-17 HIGH 9.3 CVE-2009-1392EPSS 9% The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a de… Firefox after 2.0.0.19 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1832EPSS 9% Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory c… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1833EPSS 9% The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a d… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1838 The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's ow… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1841 js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote a… Firefox after 3.0.10 Fix from $1,9502009-06-12