Vulnerabilities (CVE)

Filtered by CWE-20
Total 11775 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1233 2 Apple, Microsoft 2 Safari, Windows 2025-04-09 4.3 MEDIUM N/A
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.
CVE-2008-2042 1 Adobe 2 Acrobat, Acrobat Reader 2025-04-09 9.3 HIGH N/A
The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
CVE-2007-5031 1 Dibbler 1 Dibbler 2025-04-09 5.0 MEDIUM N/A
The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.
CVE-2009-2988 1 Adobe 2 Acrobat, Acrobat Reader 2025-04-09 4.3 MEDIUM N/A
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
CVE-2008-2970 1 Yektaweb 1 Academic Web Tools 2025-04-09 7.5 HIGH N/A
Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.
CVE-2008-5527 2 Eset, Microsoft 2 Smart Security, Internet Explorer 2025-04-09 9.3 HIGH N/A
ESET Smart Security, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
CVE-2009-4101 2 Didier Ernotte, Mozilla 2 Inforss, Firefox 2025-04-09 9.3 HIGH N/A
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
CVE-2008-5669 1 Textpattern 1 Textpattern 2025-04-09 5.0 MEDIUM N/A
index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter.
CVE-2008-5526 2 Drweb, Microsoft 2 Anti-virus, Internet Explorer 2025-04-09 9.3 HIGH N/A
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
CVE-2009-0879 2 Ibm, Microsoft 2 Director, Windows 2025-04-09 5.0 MEDIUM N/A
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.
CVE-2008-5524 2 Microsoft, Quickheal 2 Internet Explorer, Cat Quickheal 2025-04-09 9.3 HIGH N/A
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
CVE-2006-2219 1 Phpbb Group 1 Phpbb 2025-04-09 5.0 MEDIUM N/A
phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.
CVE-2008-0718 1 Sun 1 Solaris 2025-04-09 4.7 MEDIUM N/A
Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.
CVE-2007-4516 1 Symantec Veritas 1 Storage Foundation 2025-04-09 4.3 MEDIUM N/A
The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation 5.0 for Windows allows remote attackers to cause a denial of service (daemon crash or hang) via malformed packets.
CVE-2007-6242 1 Adobe 1 Flash Player 2025-04-09 6.8 MEDIUM N/A
Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."
CVE-2009-1350 1 Novell 1 Netidentity Client1.2.3 2025-04-09 10.0 HIGH N/A
Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer.
CVE-2007-4459 1 Cisco 2 Voip Phone Cp-7940, Voip Phone Cp-7960 2025-04-09 7.1 HIGH N/A
Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.
CVE-2008-2401 1 Sun 1 Java Active Server 2025-04-09 7.5 HIGH N/A
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications.
CVE-2006-5265 1 Microsoft 1 Dynamics Gp 2025-04-09 5.0 MEDIUM N/A
Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message.
CVE-2008-1744 1 Cisco 2 Unified Callmanager, Unified Communications Manager 2025-04-09 7.8 HIGH N/A
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.