Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1325 1 Vax Vms 1 Sas System 2025-04-03 7.2 HIGH N/A
SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.
CVE-2006-0019 1 Kde 1 Kde 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
CVE-2005-0994 1 Early Impact 1 Productcart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp. NOTE: it is possible that item (2) is the result of a typo or editing error from the original research report.
CVE-2001-1190 1 Mandrakesoft 1 Mandrake Linux 2025-04-03 4.6 MEDIUM N/A
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.
CVE-2000-0430 1 Mcmurtrey Whitaker And Associates 1 Cart32 2025-04-03 5.0 MEDIUM N/A
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
CVE-2000-0330 1 Microsoft 2 Windows 95, Windows 98 2025-04-03 7.6 HIGH N/A
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
CVE-2006-0411 1 Claroline 1 Claroline 2025-04-03 10.0 HIGH N/A
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.
CVE-2006-4795 1 Hp 1 Hp-ux 2025-04-03 4.6 MEDIUM N/A
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.
CVE-2001-1182 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.
CVE-2005-2190 1 Comersus Open Technologies 1 Comersus Cart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.
CVE-2006-0921 1 Fckeditor 1 Fckeditor 2025-04-03 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.
CVE-2001-0782 1 Kde 1 Ktv 2025-04-03 7.2 HIGH N/A
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.
CVE-2000-0089 1 Microsoft 1 Windows Nt 2025-04-03 2.1 LOW N/A
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
CVE-1999-1153 1 Hamcards Postcard Cgi 1 Hamcards Postcard Cgi 2025-04-03 7.5 HIGH N/A
HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
CVE-2002-1615 1 Hp 2 Hp-ux, Tru64 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.
CVE-2002-2134 1 Peel 1 Peel 2025-04-03 5.0 MEDIUM N/A
haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.
CVE-2001-0277 1 Working Resources Inc. 1 Badblue 2025-04-03 10.0 HIGH N/A
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
CVE-2005-0146 1 Mozilla 2 Firefox, Mozilla 2025-04-03 5.0 MEDIUM N/A
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
CVE-2006-2928 1 Cms-bandits 1 Cms-bandits 2025-04-03 5.1 MEDIUM N/A
Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter in (1) dialogs/img.php and (2) dialogs/td.php.
CVE-2003-1268 1 Urlogy 1 A.shop.kart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.