Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2238 1 Ibm 1 Aix 2025-04-03 2.1 LOW N/A
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
CVE-2004-2594 1 Id Software 1 Quake Ii Server Windows 2025-04-03 5.0 MEDIUM N/A
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "\/" in a pathname argument, as demonstrated by "download \/server.cfg".
CVE-2002-1112 1 Mantis 1 Mantis 2025-04-03 5.0 MEDIUM N/A
Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.
CVE-2006-2721 1 Variomat 1 Variomat 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in news.php in VARIOMAT allows remote attackers to inject arbitrary HTML or web script via the subcat parameter. NOTE: this issue might be resultant from SQL injection.
CVE-2004-0706 1 Mozilla 1 Bugzilla 2025-04-03 2.1 LOW N/A
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.
CVE-2004-1609 2 Best Software, Saleslogix Corporation 2 Saleslogix, Saleslogix 2025-04-03 5.0 MEDIUM N/A
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
CVE-2005-2231 1 High Availability Linux Project 1 Heartbeat 2025-04-03 2.1 LOW N/A
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-1999-1325 1 Vax Vms 1 Sas System 2025-04-03 7.2 HIGH N/A
SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.
CVE-2006-0019 1 Kde 1 Kde 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
CVE-2005-0994 1 Early Impact 1 Productcart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp. NOTE: it is possible that item (2) is the result of a typo or editing error from the original research report.
CVE-2001-1190 1 Mandrakesoft 1 Mandrake Linux 2025-04-03 4.6 MEDIUM N/A
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.
CVE-2000-0430 1 Mcmurtrey Whitaker And Associates 1 Cart32 2025-04-03 5.0 MEDIUM N/A
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
CVE-2000-0330 1 Microsoft 2 Windows 95, Windows 98 2025-04-03 7.6 HIGH N/A
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
CVE-2006-0411 1 Claroline 1 Claroline 2025-04-03 10.0 HIGH N/A
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.
CVE-2006-4795 1 Hp 1 Hp-ux 2025-04-03 4.6 MEDIUM N/A
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.
CVE-2001-1182 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.
CVE-2005-2190 1 Comersus Open Technologies 1 Comersus Cart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.
CVE-2006-0921 1 Fckeditor 1 Fckeditor 2025-04-03 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.
CVE-2001-0782 1 Kde 1 Ktv 2025-04-03 7.2 HIGH N/A
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.
CVE-2000-0089 1 Microsoft 1 Windows Nt 2025-04-03 2.1 LOW N/A
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.