Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6185 | 1 Noticeware | 1 Noticeware Email Server Ng | 2017-09-29 | 5.0 MEDIUM | N/A |
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | |||||
CVE-2008-6829 | 1 Vicftps | 1 Vicftps | 2017-09-29 | 5.0 MEDIUM | N/A |
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031. | |||||
CVE-2008-4380 | 1 Samsung | 1 Dvr Shr2040 | 2017-09-29 | 7.8 HIGH | N/A |
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and "/x" characters. | |||||
CVE-2008-4295 | 2 Htc, Microsoft | 3 Mda, Wiza, Windows Mobile | 2017-09-29 | 5.4 MEDIUM | N/A |
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices. | |||||
CVE-2008-4428 | 1 Phlatline | 1 Personal Information Manager | 2017-09-29 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory. | |||||
CVE-2008-5712 | 1 Kde | 1 Konqueror | 2017-09-29 | 5.0 MEDIUM | N/A |
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514. | |||||
CVE-2008-5705 | 1 Verlihub-project | 1 Verlihub | 2017-09-29 | 9.3 HIGH | N/A |
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument. | |||||
CVE-2008-5678 | 1 Fdgroup | 1 Olib7 Webview | 2017-09-29 | 4.0 MEDIUM | N/A |
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files. | |||||
CVE-2008-4770 | 1 Realvnc | 1 Realvnc | 2017-09-29 | 10.0 HIGH | N/A |
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type." | |||||
CVE-2008-4514 | 1 Konqueror | 1 Konqueror | 2017-09-29 | 5.0 MEDIUM | N/A |
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error. | |||||
CVE-2008-5937 | 1 Zkesoft | 1 Ayeview | 2017-09-29 | 7.8 HIGH | N/A |
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values. | |||||
CVE-2008-4137 | 1 Php Crawler | 1 Php Crawler | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter. | |||||
CVE-2008-5002 | 1 Chilkat Software | 1 Chilkat Crypt Activex Control | 2017-09-29 | 9.3 HIGH | N/A |
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-5677 | 1 Kwalbum | 1 Kwalbum | 2017-09-29 | 7.1 HIGH | N/A |
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-4136 | 1 Michael Roth Software | 1 Pftp | 2017-09-29 | 5.0 MEDIUM | N/A |
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames. | |||||
CVE-2008-5730 | 1 Netcat | 1 Netcat | 2017-09-29 | 7.5 HIGH | N/A |
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors involving (1) a %0a sequence in a cookie and (2) the add.php file. | |||||
CVE-2008-4878 | 1 Mywebcards | 1 Webcards | 2017-09-29 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file. | |||||
CVE-2008-4363 | 1 Deslock | 1 Deslock | 2017-09-29 | 7.2 HIGH | N/A |
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended. | |||||
CVE-2008-4318 | 1 Project-observer | 1 Observer | 2017-09-29 | 10.0 HIGH | N/A |
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php. | |||||
CVE-2008-5732 | 1 Kafooeyblog | 1 Kafooeyblog | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. |