Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3763 1 Dieselscripts 1 Diesel Joke Site 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-1999-0890 1 Ihtml Merchant 1 Ihtml Merchant 2025-04-03 7.5 HIGH N/A
iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.
CVE-2003-1238 1 Nuked-klan 1 Nuked-klan 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.
CVE-2006-3217 1 Jaguarsoft 1 Jaguaredit 2025-04-03 2.6 LOW N/A
JaguarEditControl (JEdit) ActiveX Control 1.1.0.20 and earlier allows remote attackers to obtain sensitive information, such as the username and MAC and IP addresses, by setting the test field to certain values such as 2404 or 2790, then reading the information from the .JText field.
CVE-2002-0801 1 Macromedia 1 Jrun 2025-04-03 10.0 HIGH N/A
Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.
CVE-2003-1305 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.
CVE-2000-0165 1 Etl 1 Delegate 2025-04-03 7.5 HIGH N/A
The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.
CVE-2002-0592 1 Aol 1 Instant Messenger 2025-04-03 7.5 HIGH N/A
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user.
CVE-2002-0152 1 Microsoft 6 Entourage, Excel, Ie and 3 more 2025-04-03 7.5 HIGH N/A
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
CVE-2005-2409 1 Nbsmtp 1 Nbsmtp 2025-04-03 7.5 HIGH N/A
Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.
CVE-2005-1051 1 Punbb 1 Punbb 2025-04-03 6.5 MEDIUM N/A
SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.
CVE-2004-0132 1 Visualshapers 1 Ezcontents 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.
CVE-2000-0933 1 Microsoft 1 Windows 2000 2025-04-03 4.6 MEDIUM N/A
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
CVE-2004-1539 1 Gearbox Software 1 Halo Combat Evolved 2025-04-03 5.0 MEDIUM N/A
Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.
CVE-2005-3449 1 Oracle 1 Application Server 2025-04-03 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.
CVE-2005-2646 1 Xerox 20 Document Centre 220, Document Centre 230, Document Centre 240 and 17 more 2025-04-03 6.4 MEDIUM N/A
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or read files via unknown vectors involving crafted HTTP requests.
CVE-2004-2642 1 Nathaniel Bray 1 Yeemp 2025-04-03 6.4 MEDIUM N/A
Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.
CVE-2001-1347 1 Microsoft 1 Windows 2000 2025-04-03 4.6 MEDIUM N/A
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.
CVE-2002-0329 1 Snitz Communications 1 Snitz Forums 2000 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.
CVE-2006-0343 1 Hitachi 2 Jpi Netsight Ii Port Discovery Advance, Jpi Netsight Ii Port Discovery Standard 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".