Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29520 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1310 1 Eaden Mckee 1 Bblog 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
CVE-2006-4827 1 Vmist 1 Downstat 2025-04-03 5.1 MEDIUM N/A
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.
CVE-2002-1799 1 Phprank 1 Phprank 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter.
CVE-2002-0294 1 Alcatel-lucent 1 Omnipcx 2025-04-03 2.1 LOW N/A
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
CVE-2004-1656 1 Comersus Open Technologies 1 Comersus Cart 2025-04-03 5.0 MEDIUM N/A
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.
CVE-1999-1223 1 Microsoft 1 Internet Information Server 2025-04-03 5.0 MEDIUM N/A
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
CVE-2006-4540 1 Learn.com 1 Learncenter 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2005-4584 1 Bzflag 1 Bzflag Server 2025-04-03 5.0 MEDIUM N/A
BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character.
CVE-2005-0644 1 Mcafee 1 Antivirus Engine 2025-04-03 7.5 HIGH N/A
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.
CVE-2001-1181 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.
CVE-2005-4685 1 Mozilla 2 Firefox, Mozilla 2025-04-03 6.4 MEDIUM N/A
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.
CVE-2001-0873 1 Ian Lance Taylor 1 Taylor Uucp 2025-04-03 7.2 HIGH N/A
uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.
CVE-2006-0947 1 Thomson 1 Speedtouch 2025-04-03 7.5 HIGH N/A
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.
CVE-2001-0831 1 Oracle 1 Database Server 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.
CVE-2001-0855 1 Rational Software 1 Clearcase 2025-04-03 7.2 HIGH N/A
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.
CVE-2006-1253 1 Glftpd 1 Glftpd 2025-04-03 7.5 HIGH N/A
Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostname that appears to be an IP address.
CVE-2003-1328 1 Microsoft 2 Ie, Internet Explorer 2025-04-03 7.5 HIGH N/A
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."
CVE-1999-0492 2025-04-03 10.0 HIGH N/A
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
CVE-1999-0419 2025-04-03 5.0 MEDIUM N/A
When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.
CVE-1999-0204 1 Eric Allman 1 Sendmail 2025-04-03 10.0 HIGH N/A
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.