Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0671 1 Roxen 1 Webserver 2025-04-03 5.0 MEDIUM N/A
Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.
CVE-2000-1098 1 Sonicwall 1 Soho Firewall 2025-04-03 5.0 MEDIUM N/A
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.
CVE-2001-1011 1 Mambo 1 Mambo Site Server 2025-04-03 10.0 HIGH N/A
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.
CVE-2006-1340 1 Cutephp 1 Cutenews 2025-04-03 5.0 MEDIUM N/A
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
CVE-2001-0917 1 Apache 1 Tomcat 2025-04-03 5.0 MEDIUM N/A
Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
CVE-2004-1843 1 Expinion.net 1 Member Management System 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.
CVE-2005-0795 1 Hola 1 Holacms 2025-04-03 5.0 MEDIUM N/A
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.
CVE-2002-1954 1 Php 1 Php 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.
CVE-2005-2217 1 Craig Dansie 1 Dansie Shopping Cart 2025-04-03 5.0 MEDIUM N/A
Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.
CVE-2005-3575 1 Cynox 1 Cyphor 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2001-0955 1 Xfree86 Project 1 X11r6 2025-04-03 7.2 HIGH N/A
Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.
CVE-2001-1149 1 Panda 1 Panda Antivirus Platinum 2025-04-03 5.0 MEDIUM N/A
Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file.
CVE-2004-0318 1 Platform 1 Lsf 2025-04-03 10.0 HIGH N/A
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.
CVE-2006-1434 1 Annuaire 1 Directory 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter).
CVE-2000-0106 1 Easycart 1 Easycart 2025-04-03 7.5 HIGH N/A
The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2001-1300 1 Dynu Systems Inc. 1 Dynu Ftp Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.
CVE-2001-1093 1 Compaq 1 Tru64 2025-04-03 7.2 HIGH N/A
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.
CVE-2006-2639 1 Phpsimplechoose 1 Phpsimplechoose 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element.
CVE-1999-1329 1 Redhat 1 Linux 2025-04-03 7.2 HIGH N/A
Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.
CVE-2005-3426 1 Cisco 1 Content Services Switch 11500 2025-04-03 5.0 MEDIUM N/A
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.