Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1325 1 Microsoft 2 Internet Explorer, Outlook Express 2025-04-03 7.5 HIGH N/A
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
CVE-2006-0796 1 Clever Copy 1 Clever Copy 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2000-1238 1 Bea 1 Weblogic Server 2025-04-03 7.5 HIGH N/A
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
CVE-1999-0283 2025-04-03 10.0 HIGH N/A
The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-2005-4740 1 Ibm 1 Db2 Universal Database 2025-04-03 4.0 MEDIUM N/A
IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by "connecting from a downlevel client."
CVE-2005-0239 1 Squirrelmail 1 S Mime Plugin 2025-04-03 7.5 HIGH N/A
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
CVE-2006-0153 1 427bb 1 Fourtwosevenbb 2025-04-03 7.5 HIGH N/A
427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.
CVE-2002-1733 1 Prospero Technologies 1 Prospero Message Board 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post.
CVE-2005-1900 1 Sawmill 1 Sawmill 2025-04-03 7.5 HIGH N/A
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.
CVE-2004-1337 3 Conectiva, Gnu, Ubuntu 3 Linux, Realtime Linux Security Module, Ubuntu Linux 2025-04-03 7.2 HIGH N/A
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.
CVE-2005-4695 1 Symantec 1 Brightmail Antispam 2025-04-03 5.0 MEDIUM N/A
Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.
CVE-1999-0446 1 Netbsd 1 Netbsd 2025-04-03 2.1 LOW N/A
Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.
CVE-2006-0561 1 Cisco 1 Secure Access Control Server 2025-04-03 7.2 HIGH N/A
Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.
CVE-2005-0675 1 Phpoutsourcing 1 Zorum 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.
CVE-2004-1794 1 Vcard4j 1 Vcard4j 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.
CVE-2004-0062 1 Fishnet 1 Fishcart 2025-04-03 7.5 HIGH N/A
Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.
CVE-1999-0220 2025-04-03 10.0 HIGH N/A
Attackers can do a denial of service of IRC by crashing the server.
CVE-2004-0497 7 Conectiva, Gentoo, Linux and 4 more 9 Linux, Linux, Linux Kernel and 6 more 2025-04-03 2.1 LOW N/A
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
CVE-2001-1209 1 Abe Timmerman 1 Zml.cgi 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2005-3813 1 Mailenable 2 Mailenable Enterprise, Mailenable Professional 2025-04-03 4.0 MEDIUM N/A
IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.