A vulnerability has been found in Python PIP up to 1.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the component DNS Query Handler. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2013-5123. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in NCH Software NCH Software Classic FTP 1.02 and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2008-2894. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Issuetracker phpBugTracker up to 1.6.x. This vulnerability affects unknown code. The manipulation as part of Parameter leads to sql injection.
This vulnerability was named CVE-2015-2147. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
Currently trending CVE - hypeScore: 1 - Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise
Currently trending CVE - hypeScore: 1 - An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.
Currently trending CVE - hypeScore: 1 - A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device.
This vulnerability exists because proper authorization is not enforced upon REST API
A vulnerability was found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality of the component WebRTC. The manipulation as part of HTML Page leads to out-of-bounds read.
This vulnerability is handled as CVE-2018-6129. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rtscanner of the component Folder Watch List Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-0720. The attack needs to be approached locally. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in pfSense up to 2.2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file system_firmware_restorefullbackup.php of the component WebGUI. The manipulation of the argument deletefile leads to cross-site request forgery.
This vulnerability is handled as CVE-2015-2295. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Adobe Flash Player up to 25.0.0.171 and classified as critical. Affected by this issue is some unknown functionality of the component Image Decoder. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-3077. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Media-products Bild Flirt Community 2.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument id leads to sql injection.
The identification of this vulnerability is CVE-2010-0955. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in MyBB 1.6.6. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation of the argument conditions[usergroup][] leads to sql injection.
This vulnerability is handled as CVE-2012-5909. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Powie Pforum 1.11/1.12/1.13/1.14. It has been declared as problematic. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument Username leads to basic cross site scripting.
This vulnerability was named CVE-2002-0319. The attack can be initiated remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in AltaVista Search Intranet 2.0b/2.3a. This issue affects some unknown processing of the file query.cgi. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2000-0039. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Foxweb 2.5. Affected is an unknown function in the library foxweb.dll of the file foxweb.exe of the component URL Handler. The manipulation of the argument PATH_INFO leads to memory corruption.
This vulnerability is traded as CVE-2003-0762. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as problematic was found in Zoidcom 0.6.5/0.6.7. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is known as CVE-2007-4358. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Stefan Ritt Elog Web Logbook up to 2.5.6. Affected by this vulnerability is the function decode_post. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2005-0439. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.