Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.6 CVE-2007-3606EPSS 8% Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote att… Enjoysap No fix yet Fix from $1,9502007-07-06 MEDIUM 5.0 CVE-2007-3607 Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) … Enjoysap No fix yet Fix from $1,6002007-07-06 MEDIUM 5.0 CVE-2007-3608 Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vecto… Enjoysap No fix yet Fix from $1,6002007-07-06 HIGH 10.0 CVE-2007-1916EPSS 7% Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code … Rfc Library Mitigation only Fix from $1,9502007-04-10 HIGH 10.0 CVE-2007-1917EPSS 7% Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitr… Rfc Library Mitigation only Fix from $1,9502007-04-10 HIGH 7.5 CVE-2007-1915 Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary c… Rfc Library Mitigation only Fix from $1,9502007-04-10 MEDIUM 5.0 CVE-2007-1913 The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users an… Rfc Library No fix yet Fix from $1,6002007-04-10 MEDIUM 5.0 CVE-2007-1918 The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC ser… Rfc Library No fix yet Fix from $1,6002007-04-10 MEDIUM 5.0 CVE-2006-6010EPSS 14% SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceiv… Sap Web Application Server Mitigation only Fix from $1,6002006-11-21 MEDIUM 5.0 CVE-2006-6011 Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash)… Sap Web Application Server Mitigation only Fix from $1,6002006-11-21 MEDIUM 6.8 CVE-2006-5114 Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject ar… Internet Transaction Server No fix yet Fix from $1,6002006-10-03 HIGH 7.5 CVE-2006-4133EPSS 6% Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial o… Internet Graphics Server Mitigation only Fix from $1,9502006-08-14 MEDIUM 5.0 CVE-2006-4134 Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attac… Internet Graphics Server No fix yet Fix from $1,6002006-08-14 MEDIUM 6.4 CVE-2006-1039 SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive au… Sap Web Application Server Mitigation only Fix from $1,6002006-03-07 MEDIUM 6.4 CVE-2006-0732 Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullNa… Business Connector Mitigation only Fix from $1,6002006-02-16 HIGH 7.5 CVE-2005-4815 SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before… Sap R 3 Mitigation only Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-3633 HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitra… Sap Web Application Server No fix yet Fix from $1,6002005-11-16 MEDIUM 5.0 CVE-2005-3634EPSS 18% frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to a… Sap Web Application Server No fix yet Fix from $1,6002005-11-16 HIGH 7.5 CVE-2002-1577 SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2… Sap R 3 Mitigation only Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1035 The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b… Sap R 3 Mitigation only Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1039 Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) M… Mysap Business Suite Mitigation only Fix from $1,9502004-04-15 MEDIUM 6.8 CVE-2003-0749 Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arb… Internet Transaction Server No fix yet Fix from $1,6002003-10-20 MEDIUM 5.0 CVE-2003-0747 wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as direct… Internet Transaction Server No fix yet Fix from $1,6002003-10-20 MEDIUM 5.0 CVE-2003-0748EPSS 8% Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary fi… Internet Transaction Server No fix yet Fix from $1,6002003-10-20