Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29516 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3063 1 Unu Networks 1 Mailgust 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.
CVE-2003-1011 1 Apple 1 Mac Os X 2025-04-03 7.2 HIGH N/A
Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.
CVE-1999-0341 2 Debian, Slackware 2 Debian Linux, Slackware Linux 2025-04-03 7.2 HIGH N/A
Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.
CVE-2006-1700 1 Aweb 1 Scripts Seller 2025-04-03 7.5 HIGH N/A
Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication.
CVE-1999-0019 7 Data General, Ibm, Ncr and 4 more 10 Dg Ux, Aix, Mp-ras and 7 more 2025-04-03 5.0 MEDIUM N/A
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0209 1 Sun 1 Sunos 2025-04-03 5.0 MEDIUM N/A
The SunView (SunTools) selection_svc facility allows remote users to read files.
CVE-1999-0916 1 Webtrends 5 Webtrends Enterprise Suite, Webtrends For Firewalls, Webtrends Log Analyzer and 2 more 2025-04-03 2.1 LOW N/A
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
CVE-2003-0360 1 Debian 1 Debian Linux 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2006-0915 1 Mozilla 1 Bugzilla 2025-04-03 7.5 HIGH N/A
Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.
CVE-1999-0298 2 Slackware, Sun 2 Slackware Linux, Sunos 2025-04-03 7.5 HIGH N/A
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.
CVE-2006-3604 1 Seyeon 1 Flexwatch Network Camera 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.
CVE-2006-0726 1 Cpg-nuke 1 Dragonfly Cms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.
CVE-2005-0497 1 Adp 1 Elite System Max 9000 2025-04-03 7.2 HIGH N/A
ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.
CVE-2002-0883 1 Compaq 1 Proliant Bl E-class Integrated Administrator Firmware 2025-04-03 7.2 HIGH N/A
Vulnerability in Compaq ProLiant BL e-Class Integrated Administrator 1.0 and 1.10, allows authenticated users with Telnet, SSH, or console access to conduct unauthorized activities.
CVE-2000-0004 1 Zbsoft 1 Zbserver 2025-04-03 5.0 MEDIUM N/A
ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.
CVE-2004-0908 1 Mozilla 2 Mozilla, Thunderbird 2025-04-03 4.0 MEDIUM N/A
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
CVE-2002-0521 1 Asp-nuke 1 Asp-nuke 2025-04-03 5.1 MEDIUM N/A
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp.
CVE-2006-1850 1 Skymarx Solutions 1 Xflow 2025-04-03 2.6 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page parameter to customer_area/index.cgi.
CVE-2001-0139 5 Caldera, Debian, Immunix and 2 more 7 Openlinux Desktop, Openlinux Edesktop, Openlinux Eserver and 4 more 2025-04-03 1.2 LOW N/A
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
CVE-2005-1301 1 Nprotect 1 Netizen 2025-04-03 2.6 LOW N/A
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.