Total
29520 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-1310 | 1 Eaden Mckee | 1 Bblog | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |||||
CVE-2006-4827 | 1 Vmist | 1 Downstat | 2025-04-03 | 5.1 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php. | |||||
CVE-2002-1799 | 1 Phprank | 1 Phprank | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter. | |||||
CVE-2002-0294 | 1 Alcatel-lucent | 1 Omnipcx | 2025-04-03 | 2.1 LOW | N/A |
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. | |||||
CVE-2004-1656 | 1 Comersus Open Technologies | 1 Comersus Cart | 2025-04-03 | 5.0 MEDIUM | N/A |
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter. | |||||
CVE-1999-1223 | 1 Microsoft | 1 Internet Information Server | 2025-04-03 | 5.0 MEDIUM | N/A |
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. | |||||
CVE-2006-4540 | 1 Learn.com | 1 Learncenter | 2025-04-03 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||||
CVE-2005-4584 | 1 Bzflag | 1 Bzflag Server | 2025-04-03 | 5.0 MEDIUM | N/A |
BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character. | |||||
CVE-2005-0644 | 1 Mcafee | 1 Antivirus Engine | 2025-04-03 | 7.5 HIGH | N/A |
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643. | |||||
CVE-2001-1181 | 1 Hp | 1 Hp-ux | 2025-04-03 | 7.2 HIGH | N/A |
Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges. | |||||
CVE-2005-4685 | 1 Mozilla | 2 Firefox, Mozilla | 2025-04-03 | 6.4 MEDIUM | N/A |
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site. | |||||
CVE-2001-0873 | 1 Ian Lance Taylor | 1 Taylor Uucp | 2025-04-03 | 7.2 HIGH | N/A |
uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option. | |||||
CVE-2006-0947 | 1 Thomson | 1 Speedtouch | 2025-04-03 | 7.5 HIGH | N/A |
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface. | |||||
CVE-2001-0831 | 1 Oracle | 1 Database Server | 2025-04-03 | 4.6 MEDIUM | N/A |
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access. | |||||
CVE-2001-0855 | 1 Rational Software | 1 Clearcase | 2025-04-03 | 7.2 HIGH | N/A |
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable. | |||||
CVE-2006-1253 | 1 Glftpd | 1 Glftpd | 2025-04-03 | 7.5 HIGH | N/A |
Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address. | |||||
CVE-2003-1328 | 1 Microsoft | 2 Ie, Internet Explorer | 2025-04-03 | 7.5 HIGH | N/A |
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality." | |||||
CVE-1999-0492 | 2025-04-03 | 10.0 HIGH | N/A | ||
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | |||||
CVE-1999-0419 | 2025-04-03 | 5.0 MEDIUM | N/A | ||
When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. | |||||
CVE-1999-0204 | 1 Eric Allman | 1 Sendmail | 2025-04-03 | 10.0 HIGH | N/A |
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. |