Vulnerabilities (CVE)

Filter

114171 total CVE
CVE Vendors Products Updated CVSS
CVE-2018-18377 2018-10-16 N/A
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
CVE-2018-18376 2018-10-16 N/A
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
CVE-2018-18375 2018-10-16 N/A
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
CVE-2018-18374 2018-10-16 N/A
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2008-5205 1 Wellyblog 1 Wellyblog 2018-10-15 4.3
Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.
CVE-2008-2543 1 Asterisk 1 Asterisk-addons 2018-10-15 5.0
The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is intended solely for localhost communication, and interprets some TCP application-data fields as...
CVE-2008-1000 1 Apple 2 Mac Os X, Mac Os X Server 2018-10-15 8.5
Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.
CVE-2008-0986 1 Google 1 Android Sdk 2018-10-15 7.5
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.
CVE-2008-0985 1 Google 1 Android Sdk 2018-10-15 6.8
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than...
CVE-2008-0984 2 Miro, Videolan 2 Vlc Media Player, Miro Player 2018-10-15 9.3
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
CVE-2008-0983 1 Lighttpd 1 Lighttpd 2018-10-15 5.0
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an...
CVE-2008-0982 1 Spyce 1 Spyce 2018-10-15 5.8
Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message.
CVE-2008-0981 1 Spyce 1 Spyce 2018-10-15 6.4
Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
CVE-2008-0980 1 Spyce 1 Spyce 2018-10-15 4.3
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to...
CVE-2008-0979 2 Hp, Double-take Software 2 Double-take, Storageworks Double-take 2018-10-15 5.0
Stack consumption vulnerability in Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain packet that...
CVE-2008-0978 1 Double-take Software 1 Double-take 2018-10-15 5.0
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain sensitive information via a packet of type (1) 0x2728, which provides operating system and path...
CVE-2008-0977 1 Double-take Software 1 Double-take 2018-10-15 5.0
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain long packet that triggers an attempt to allocate a...
CVE-2008-0976 2 Hp, Double-take Software 2 Double-take, Storageworks Double-take 2018-10-15 5.0
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as...
CVE-2008-0975 1 Double-take Software 1 Double-take 2018-10-15 5.0
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (CPU consumption) via a -1 value in the field that specifies the size of the...
CVE-2008-0974 2 Hp, Double-take Software 2 Double-take, Storageworks Double-take 2018-10-15 5.0
Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon termination) via (1) a large vector<T> value, which raises a "vector<T>...