Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4824 1 Quicksilver Forums 1 Quicksilver Forums 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.
CVE-2006-2355 1 Ipswitch 1 Whatsup Professional 2025-04-03 5.0 MEDIUM N/A
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-1999-1140 1 Alec Muffet 1 Cracklib 2025-04-03 7.2 HIGH N/A
Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.
CVE-2001-0224 1 Brightstation 1 Muscat Empower 2025-04-03 5.0 MEDIUM N/A
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
CVE-1999-0715 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
CVE-2005-4310 1 Ssh 1 Tectia Server 2025-04-03 7.5 HIGH N/A
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
CVE-2004-1922 1 Microsoft 1 Internet Explorer 2025-04-03 2.6 LOW N/A
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
CVE-2005-2234 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
CVE-2001-1455 1 Netegrity 1 Siteminder 2025-04-03 7.5 HIGH N/A
Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.
CVE-2005-0764 1 Marc Lehmann 1 Rxvt-unicode 2025-04-03 7.5 HIGH N/A
Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.
CVE-2001-1325 1 Microsoft 2 Internet Explorer, Outlook Express 2025-04-03 7.5 HIGH N/A
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
CVE-2006-0796 1 Clever Copy 1 Clever Copy 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2000-1238 1 Bea 1 Weblogic Server 2025-04-03 7.5 HIGH N/A
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
CVE-1999-0283 2025-04-03 10.0 HIGH N/A
The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-2005-4740 1 Ibm 1 Db2 Universal Database 2025-04-03 4.0 MEDIUM N/A
IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by "connecting from a downlevel client."
CVE-2005-0239 1 Squirrelmail 1 S Mime Plugin 2025-04-03 7.5 HIGH N/A
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
CVE-2006-0153 1 427bb 1 Fourtwosevenbb 2025-04-03 7.5 HIGH N/A
427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.
CVE-2002-1733 1 Prospero Technologies 1 Prospero Message Board 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post.
CVE-2005-1900 1 Sawmill 1 Sawmill 2025-04-03 7.5 HIGH N/A
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.
CVE-2004-1337 3 Conectiva, Gnu, Ubuntu 3 Linux, Realtime Linux Security Module, Ubuntu Linux 2025-04-03 7.2 HIGH N/A
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.