Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29800 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1552 1 Geovision 1 Digital Surveillance System 2025-04-03 5.0 MEDIUM N/A
GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.
CVE-2001-1203 1 Alessandro Rubini 1 Gpm 2025-04-03 7.2 HIGH N/A
Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.
CVE-2003-0720 1 University Of Washington 1 Pine 2025-04-03 7.5 HIGH N/A
Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
CVE-2006-2174 1 Virtual Hosting Control System 1 Virtual Hosting Control System 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.
CVE-2005-3737 1 Inkscape 1 Inkscape 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
CVE-2003-0165 1 Gnome 1 Eog 2025-04-03 4.6 MEDIUM N/A
Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.
CVE-2004-1454 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.
CVE-2005-2290 1 Wps 1 Web Portal System 2025-04-03 10.0 HIGH N/A
wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.
CVE-2002-1768 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985.
CVE-2004-1097 1 Cherokee 1 Cherokee Httpd 2025-04-03 10.0 HIGH N/A
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
CVE-2001-0985 1 Hassan Consulting 1 Shopping Cart 2025-04-03 7.5 HIGH N/A
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
CVE-2003-1303 1 Php 1 Php 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.
CVE-2000-0067 1 Cybercash 1 Merchant Connection Kit 2025-04-03 2.1 LOW N/A
CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.
CVE-2005-1626 1 Pico Server 1 Pico Server 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.
CVE-2005-1022 1 Macromedia 1 Coldfusion 2025-04-03 5.0 MEDIUM N/A
ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.
CVE-1999-0576 1 Microsoft 1 Windows Nt 2025-04-03 7.5 HIGH N/A
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
CVE-2005-0230 1 Mozilla 1 Firefox 2025-04-03 5.1 MEDIUM N/A
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
CVE-2006-2310 1 New Atlanta Communications 2 Bluedragon Server, Bluedragon Server Jx 2025-04-03 5.0 MEDIUM N/A
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.
CVE-2006-3737 1 Swsoft 1 Plesk Control Panel 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.
CVE-2006-4525 1 Devellion 1 Cubecart 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.