The Open Source Vulnerability Database

OSVDB is an independent and open source database created by and for the community.
Our goal is to provide accurate, detailed, current, and unbiased technical information.

Latest OSVDB Vulnerabilities

49047 Disclosed: 2008-09-30 LiveUpdate UpdateEngine ActiveX (LiveUpdate16.DLL) ApplyPatch Method Arbitrary Program Execution
49046 Disclosed: 2008-10-10 NoticeWare Email Server POP3 Connection Saturation Remote DoS
49045 Disclosed: 2008-10-12 GuildFTPd LIST Command Handling Remote Overflow
49044 Disclosed: 2008-10-09 ScriptsEz Mini Hosting Panel members.php dir Variable Traversal Arbitrary File Access
49043 Disclosed: 2008-10-09 WinFTP PASV Command Handling Remote DoS
49042 Disclosed: 2008-10-07 YourOwnBux referrals.php usNick Cookie SQL Injection
49041 Disclosed: 2008-10-05 World of Warcraft Tracker Infusion Module for PHP-Fusion thisraidprogress.php INFO_RAID_ID Variable SQL Injection
49040 Disclosed: 2008-10-12 My PHP Indexer index.php d Variable Traversal Arbitrary File Access
49039 Disclosed: 2008-10-03 CCMS pages/story.php skin Variable Traveral Local File Inclusion
49038 Disclosed: 2008-10-03 CCMS header.php skin Variable Traveral Local File Inclusion

OSVDB News Feed

2008-07-31OSVDB in Vegas.....
2008-07-14OSF To Maintain Attrition.org's Data Loss Database
2008-07-07Stop using Google, it's dangerous!
2008-07-07The Black Market Code Industry
2008-07-06VDBs Devolving?
2008-06-21OSVDB Featured in the Open Source Business Resource (OSBR)
2008-06-18Coffee makers are SCADA, right?!
2008-05-30Who's to blame? The hazard of "0-day".
2008-05-24Top vulnerability researcher?
2008-05-15Layered Technologies Continued Support of OSVDB

Support OSVDB!

OSVDB needs your support! Donations get you enhanced access to the watch-list feature:

  • Watch unlimited products AND vendors, as opposed to just 10 products.
  • Receive notifications via RSS and email.

Pricing is in place for both individuals and organizations.

Visit the Support Page for details.

Sponsors

Sponsor

Member Highlight

Cji


Top Viewed Vulnerabilities this week

18293 Views: 500 Belkin 54G Routers Admin Account Default Null Password
40621 Views: 175 Simple PHP Blog (SPHPBlog) add_link.php link_id Variable CSRF
25257 Views: 172 Big Webmaster Guestbook addguest.cgi Multiple Field XSS
28946 Views: 154 Microsoft IE Vector Markup Language (VML) Arbitrary Code Execution
44643 Views: 140 Realtek HD Audio Codec Driver RTKVHDA.sys / RTKVHDA64.sys IOCTL Request Handling Overflow
821 Views: 125 Linksys Router Default Password
4030 Views: 119 TCP/IP Sequence Prediction Blind Reset Spoofing DoS
592 Views: 118 ZyXEL Multiple Routers Default Administrator Password
22297 Views: 95 VenomBoard add_post.php3 Multiple Variable SQL Injection
24120 Views: 94 ssCMS search.aspx keywords Variable XSS

Top Blogged Vulnerabilities this Month

47963 Blogs: 19 Microsoft Windows Media Player Audio File Sampling Rate Remote Code Execution
47968 Blogs: 18 Microsoft Multiple Products GDI+ WMF Image Handling Overflow
47965 Blogs: 17 Microsoft Multiple Products GDI+ VML Gradient Size Handling Overflow
47962 Blogs: 10 Microsoft Windows Media Encoder wmex.dll ActiveX Overflow
47964 Blogs: 5 Microsoft Office OneNote Protocol Handler (onenote://) URI Handling Arbitrary Code Execution
48751 Blogs: 4 Mozilla Multiple Products nsJSNPRuntime.cpp nsNPObjWrapper::GetNewOrUsed Function Memory Corruption
47836 Blogs: 4 VLC Media Player modules/access/mms/mmstu.c mms_ReceiveCommand Function Remote Overflow
47969 Blogs: 4 Microsoft Multiple Products GDI+ BMP Integer Calculation Overflow
48247 Blogs: 3 VMware Multiple Products Unspecified ActiveX Unspecified Issue (1)
47405 Blogs: 3 Microsoft Office PowerPoint Viewer Picture Index Handling Memory Corruption

Blogs provided by Technorati

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use