Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29536 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3189 1 Hotplug Cms 1 Hotplug Cms 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CVE-2006-0927 2 Jgs-xa, Woltlab 2 Jgs-gallery Addon, Burning Board 2025-04-03 2.6 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.
CVE-2006-3499 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.1 LOW N/A
The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications.
CVE-2005-2399 1 Php Surveyor 1 Php Surveyor 2025-04-03 7.5 HIGH N/A
PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.
CVE-1999-0653 2025-04-03 10.0 HIGH N/A
A component service related to NIS+ is running.
CVE-2006-4621 1 Bare Concept Media 1 Pheap Cms 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The lib/config.php vector is already covered by CVE-2006-4531.
CVE-2004-1129 1 Youngzsoft 1 Cmailserver 2025-04-03 10.0 HIGH N/A
SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.
CVE-2004-1100 1 Tips 1 Mailpost 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.
CVE-2006-3525 1 Phpcredo 1 Phcdownload 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in category.php in PHCDownload 1.0.0 Final and 1.0.0 Release Candidate 6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2004-1453 1 Gnu 1 Glibc 2025-04-03 2.1 LOW N/A
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.
CVE-2005-2435 1 Website Baker 1 Website Baker 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
CVE-2001-0533 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.
CVE-2003-0623 1 Bea 2 Tuxedo, Weblogic Server 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
CVE-2005-0885 1 Xmb Forum 1 Xmb 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.
CVE-2003-0548 2 Gnome, Redhat 4 Gdm, Enterprise Linux, Kdebase and 1 more 2025-04-03 5.0 MEDIUM N/A
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
CVE-2000-0731 1 Jeremy Arnold 1 Worm Webserver 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2002-0052 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Internet Explorer 6.0 and earlier does not properly handle VBScript in certain domain security checks, which allows remote attackers to read arbitrary files.
CVE-2000-0189 1 Allaire 1 Coldfusion Server 2025-04-03 5.0 MEDIUM N/A
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
CVE-2004-1678 1 Logicnow 1 Perldesk 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.
CVE-2004-0351 1 Spidersales 1 Spidersales 2025-04-03 2.1 LOW N/A
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.