Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Business One 2005 A HIGH 10.0
CVE-2009-4988EPSS 66%

Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2010-08-25
Crystal Reports HIGH 10.0
CVE-2010-3032EPSS 6%

Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers…

Mitigation only
Fix from $1,950 2010-08-17
Maxdb HIGH 10.0
CVE-2010-1185EPSS 15%

Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an i…

No fix yet
Fix from $1,950 2010-03-29
Sap Kernel MEDIUM 5.0
CVE-2009-4603

Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Appli…

Mitigation only
Fix from $1,600 2010-01-12
Crystal Reports Server HIGH 10.0
CVE-2009-3345

Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco…

No fix yet
Fix from $1,950 2009-09-24
Crystal Reports Server HIGH 10.0
CVE-2009-3346

Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated b…

No fix yet
Fix from $1,950 2009-09-24
Crystal Reports Server MEDIUM 5.0
CVE-2009-3344

Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown …

No fix yet
Fix from $1,600 2009-09-24
Sap Gui HIGH 9.3
CVE-2008-4830EPSS 28%

Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.4…

Patch available
Fix from $1,950 2009-04-16
Sapgui HIGH 9.3
CVE-2007-4475EPSS 40%

Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers t…

Fix: after 7.10
Fix from $1,950 2009-04-01
Sapgui HIGH 9.3
CVE-2008-4387EPSS 16%

Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…

Mitigation only
Fix from $1,950 2008-11-10
Business Objects HIGH 9.3
CVE-2007-6254EPSS 6%

Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before…

Fix: after 6.5
Fix from $1,950 2008-03-20
Maxdb HIGH 9.3
CVE-2008-0307

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown…

Mitigation only
Fix from $1,950 2008-03-11
Maxdb MEDIUM 6.9
CVE-2008-0306

sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment vari…

Mitigation only
Fix from $1,600 2008-03-11
Sapgui HIGH 10.0
CVE-2008-0620

SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LP…

Fix: after 6.28
Fix from $1,950 2008-02-06
Sapgui HIGH 7.5
CVE-2008-0621EPSS 73%

Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via l…

Fix: after 6.28
Fix from $1,950 2008-02-06
Maxdb HIGH 10.0
CVE-2008-0244EPSS 80%

SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo …

Fix: after 7.6.3_build_007
Fix from $1,950 2008-01-12
Saplpd HIGH 7.8
CVE-2006-7220

Unspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print jo…

Mitigation only
Fix from $1,950 2007-07-10
Sap Message Server HIGH 10.0
CVE-2007-3624EPSS 37%

Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in th…

Patch available
Fix from $1,950 2007-07-09
Internet Communication Manager HIGH 7.8
CVE-2007-3615

Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attack…

Patch available
Fix from $1,950 2007-07-06
Enjoysap HIGH 7.6
CVE-2007-3605EPSS 70%

Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attacke…

Patch available
Fix from $1,950 2007-07-06
Enjoysap HIGH 7.6
CVE-2007-3606EPSS 8%

Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote att…

No fix yet
Fix from $1,950 2007-07-06
Sap Db HIGH 7.5
CVE-2007-3614EPSS 70%

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execut…

Patch available
Fix from $1,950 2007-07-06
Enjoysap MEDIUM 5.0
CVE-2007-3607

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) …

No fix yet
Fix from $1,600 2007-07-06
Enjoysap MEDIUM 5.0
CVE-2007-3608

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vecto…

No fix yet
Fix from $1,600 2007-07-06
Rfc Library HIGH 10.0
CVE-2007-1916EPSS 7%

Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library HIGH 10.0
CVE-2007-1917EPSS 7%

Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library HIGH 7.8
CVE-2007-1914

The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external…

Patch available
Fix from $1,950 2007-04-10
Rfc Library HIGH 7.5
CVE-2007-1915

Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library MEDIUM 5.0
CVE-2007-1913

The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users an…

No fix yet
Fix from $1,600 2007-04-10
Rfc Library MEDIUM 5.0
CVE-2007-1918

The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC ser…

No fix yet
Fix from $1,600 2007-04-10