Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29801 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0968 1 Ncp Network Communications 1 Secure Client 2025-04-03 7.2 HIGH N/A
The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.
CVE-2005-0646 1 Php Arena 1 Panews 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
CVE-2006-0043 1 Suse 1 Suse Linux 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.
CVE-1999-1234 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
CVE-2002-0193 1 Microsoft 1 Internet Explorer 2025-04-03 7.5 HIGH N/A
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.
CVE-2006-2326 1 Onlyscript.info 1 Online Universal Payment System Script 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2000-1032 1 Checkpoint 1 Firewall-1 2025-04-03 5.0 MEDIUM N/A
The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.
CVE-2005-0876 1 Dnsmasq 1 Dnsmasq 2025-04-03 5.0 MEDIUM N/A
Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.
CVE-2006-3976 1 Broadcom 1 Etrust Antivirus Webscan 2025-04-03 9.3 HIGH N/A
Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 allows remote attackers to install arbitrary files.
CVE-2002-1759 1 Phprojekt 1 Phprojekt 2025-04-03 5.0 MEDIUM N/A
The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.
CVE-2006-4675 1 Andreas Gohr 1 Dokuwiki 2025-04-03 7.5 HIGH N/A
Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors.
CVE-2000-0539 1 Macromedia 1 Jrun 2025-04-03 6.4 MEDIUM N/A
Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.
CVE-1999-1355 1 Compaq 2 Insight Management Agent, Management Agents For Servers 2025-04-03 7.5 HIGH N/A
BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.
CVE-2000-0708 1 Pragma Systems 1 Telnetserver 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.
CVE-2004-0361 1 Apple 1 Safari 2025-04-03 5.0 MEDIUM N/A
The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.
CVE-2005-2486 1 Portailphp 1 Portailphp 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.
CVE-2005-3108 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
mm/ioremap.c in Linux 2.6 on 64-bit x86 systems allows local users to cause a denial of service or an information leak via an ioremap on a certain memory map that causes the iounmap to perform a lookup of a page that does not exist.
CVE-2006-4951 1 Neosys 1 Neon Webmail 2025-04-03 7.5 HIGH N/A
Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.
CVE-2006-0137 1 Phanatic Softwares 1 Chimera Web Portal 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2005-4602 1 Mybulletinboard 1 Mybulletinboard 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.