Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2009-4988EPSS 66% Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary co… Business One 2005 A No fix yet Fix from $1,9502010-08-25 HIGH 10.0 CVE-2010-3032EPSS 6% Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers… Crystal Reports Mitigation only Fix from $1,9502010-08-17 HIGH 10.0 CVE-2010-1185EPSS 15% Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an i… Maxdb No fix yet Fix from $1,9502010-03-29 MEDIUM 5.0 CVE-2009-4603 Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Appli… Sap Kernel Mitigation only Fix from $1,6002010-01-12 HIGH 10.0 CVE-2009-3345 Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco… Crystal Reports Server No fix yet Fix from $1,9502009-09-24 HIGH 10.0 CVE-2009-3346 Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated b… Crystal Reports Server No fix yet Fix from $1,9502009-09-24 MEDIUM 5.0 CVE-2009-3344 Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown … Crystal Reports Server No fix yet Fix from $1,6002009-09-24 HIGH 9.3 CVE-2008-4830EPSS 28% Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.4… Sap Gui Patch available Fix from $1,9502009-04-16 HIGH 9.3 CVE-2007-4475EPSS 40% Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers t… Sapgui after 7.10 Fix from $1,9502009-04-01 HIGH 9.3 CVE-2008-4387EPSS 16% Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk… Sapgui Mitigation only Fix from $1,9502008-11-10 HIGH 9.3 CVE-2007-6254EPSS 6% Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before… Business Objects after 6.5 Fix from $1,9502008-03-20 HIGH 9.3 CVE-2008-0307 Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown… Maxdb Mitigation only Fix from $1,9502008-03-11 MEDIUM 6.9 CVE-2008-0306 sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment vari… Maxdb Mitigation only Fix from $1,6002008-03-11 HIGH 10.0 CVE-2008-0620 SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LP… Sapgui after 6.28 Fix from $1,9502008-02-06 HIGH 7.5 CVE-2008-0621EPSS 73% Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via l… Sapgui after 6.28 Fix from $1,9502008-02-06 HIGH 10.0 CVE-2008-0244EPSS 80% SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo … Maxdb after 7.6.3_build_007 Fix from $1,9502008-01-12 HIGH 7.8 CVE-2006-7220 Unspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print jo… Saplpd Mitigation only Fix from $1,9502007-07-10 HIGH 10.0 CVE-2007-3624EPSS 37% Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in th… Sap Message Server Patch available Fix from $1,9502007-07-09 HIGH 7.8 CVE-2007-3615 Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attack… Internet Communication Manager Patch available Fix from $1,9502007-07-06 HIGH 7.6 CVE-2007-3605EPSS 70% Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attacke… Enjoysap Patch available Fix from $1,9502007-07-06 HIGH 7.6 CVE-2007-3606EPSS 8% Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote att… Enjoysap No fix yet Fix from $1,9502007-07-06 HIGH 7.5 CVE-2007-3614EPSS 70% Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execut… Sap Db Patch available Fix from $1,9502007-07-06 MEDIUM 5.0 CVE-2007-3607 Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) … Enjoysap No fix yet Fix from $1,6002007-07-06 MEDIUM 5.0 CVE-2007-3608 Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vecto… Enjoysap No fix yet Fix from $1,6002007-07-06 HIGH 10.0 CVE-2007-1916EPSS 7% Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code … Rfc Library Mitigation only Fix from $1,9502007-04-10 HIGH 10.0 CVE-2007-1917EPSS 7% Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitr… Rfc Library Mitigation only Fix from $1,9502007-04-10 HIGH 7.8 CVE-2007-1914 The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external… Rfc Library Patch available Fix from $1,9502007-04-10 HIGH 7.5 CVE-2007-1915 Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary c… Rfc Library Mitigation only Fix from $1,9502007-04-10 MEDIUM 5.0 CVE-2007-1913 The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users an… Rfc Library No fix yet Fix from $1,6002007-04-10 MEDIUM 5.0 CVE-2007-1918 The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC ser… Rfc Library No fix yet Fix from $1,6002007-04-10