Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29557 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2486 1 Dropbear Ssh Project 1 Dropbear Ssh 2025-04-03 7.5 HIGH N/A
The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
CVE-2004-0945 1 Mitel 1 Mitel 3300 Integrated Communication Platform 2025-04-03 5.0 MEDIUM N/A
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.
CVE-2005-3282 1 Splatt 1 Splatt Forum 2025-04-03 7.5 HIGH N/A
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
CVE-2004-0579 2 Debian, William Deich 2 Debian Linux, Super 2025-04-03 7.2 HIGH N/A
Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.
CVE-2006-3825 1 Sun 1 Solaris 2025-04-03 2.1 LOW N/A
The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.
CVE-2004-1921 1 X-micro 1 Wlan 11b Broadband Router Firmware 2025-04-03 7.5 HIGH N/A
X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.
CVE-2001-0604 1 Lotus 1 Domino R5 Server 2025-04-03 5.0 MEDIUM N/A
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.
CVE-2005-0196 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.
CVE-2005-4526 1 Clearswift 1 Mimesweeper For Web 2025-04-03 5.0 MEDIUM N/A
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
CVE-2002-0591 1 Aol 1 Instant Messenger 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
CVE-2000-0359 1 Acme Labs 1 Thttpd 2025-04-03 10.0 HIGH N/A
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
CVE-2006-0739 1 Estara 1 Softphone 2025-04-03 5.0 MEDIUM N/A
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.
CVE-2005-2246 1 Iphotoalbum 1 Iphotoalbum 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.
CVE-2005-3530 1 Antville 1 Antville 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Antville 1.1 allows remote attackers to inject arbitrary web script or HTML via the notfound.skin error document.
CVE-2002-0754 2 Freebsd, Kth 3 Freebsd, Heimdal, Heimdal 2025-04-03 7.2 HIGH N/A
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
CVE-2004-2538 1 Nilesh Dosooye 1 Phpcodegenie 2025-04-03 6.5 MEDIUM N/A
Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.
CVE-2005-3556 1 Tincan 1 Phplist 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) action parameter in (h) admin/fckphplist.php.
CVE-2004-1667 1 Gearbox Software 1 Halo Combat Evolved 2025-04-03 5.0 MEDIUM N/A
Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.
CVE-2002-1056 1 Microsoft 2 Outlook, Word 2025-04-03 7.5 HIGH N/A
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
CVE-2005-2759 1 Symantec 1 Norton Antivirus 2025-04-03 7.2 HIGH N/A
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the DiskMountNotify issue, and CVE-2005-2759 for the LiveUpdate issue.