1390 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2009-4372
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
8.8%
2009 1 PoC

AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5) storage_graphs4.php in sem/.

CVE-2009-5020
Software Genérico Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2009 1 PoC

Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2009-2878
Software Genérico Networking Cloud Windows
N/A
UNKNOWN
EPSS
2.5%
2009 1 PoC

Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted WebEx Recording Format (WRF) file, a different vulnerability than CVE-2009-2876 and CVE-2009-2879.

CVE-2009-0751
Software Genérico Cloud
N/A
UNKNOWN
EPSS
19.5%
2009 1 PoC

Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.

CVE-2009-4156
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.8%
2009 1 PoC

PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_path parameter.

CVE-2009-4588
Software Genérico Cloud
N/A
UNKNOWN
EPSS
65.0%
2009 1 PoC

Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.

CVE-2014-3486
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.

CVE-2013-6876
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2013 1 PoC

The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: this vulnerability was fixed with commit ad732f00b411b092c66a04c359da0f16ec3b387, but the version number was not changed.

CVE-2009-2024
Software Genérico Cloud
N/A
UNKNOWN
EPSS
4.0%
2009 1 PoC

Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt.

CVE-2009-4168
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
5.2%
2009 1 PoC

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.

CVE-2008-6084
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
6.0%
2008 1 PoC

Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

CVE-2008-1514
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2008 1 PoC

arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.

CVE-2008-4473
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
27.5%
2008 1 PoC

Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.

CVE-2008-3922
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
91.4%
2008 2 PoCs

awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.

CVE-2008-5080
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.4%
2008 1 PoC

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

CVE-2008-4420
Software Genérico Cloud
N/A
UNKNOWN
EPSS
6.5%
2008 2 PoCs

Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.

CVE-2013-6446
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.

CVE-2008-3714
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
4.1%
2008 3 PoCs

Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

CVE-2008-4444
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
1.9%
2008 1 PoC

Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.

CVE-2008-1765
Software Genérico Cloud
N/A
UNKNOWN
EPSS
38.3%
2008 1 PoC

Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.