Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29798 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0781 1 Php Arena 1 Pafiledb 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.
CVE-2005-1887 1 Sun 1 Solaris 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.
CVE-1999-1116 1 Sgi 1 Irix 2025-04-03 7.2 HIGH N/A
Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.
CVE-2006-4052 1 Turnkey Web Tools 1 Php Simple Shop 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4) admin/login.php, (5) admin/menu.php or (6) admin/header.php.
CVE-2005-3431 1 Rockliffe 1 Mailsite Express 2025-04-03 5.0 MEDIUM N/A
Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.
CVE-2002-1080 1 Aprelium Technologies 1 Abyss Web Server 2025-04-03 7.5 HIGH N/A
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
CVE-2004-2074 1 Bolintech 1 Dream Ftp Server 2025-04-03 5.0 MEDIUM N/A
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.
CVE-2000-0973 1 Daniel Stenberg 1 Curl 2025-04-03 10.0 HIGH N/A
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.
CVE-2005-3442 1 Oracle 1 Database Server 2025-04-03 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service.
CVE-2006-2953 1 Primoris Software 1 Officeflow 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow 2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the sqlType parameter.
CVE-2006-4384 1 Apple 1 Quicktime 2025-04-03 5.1 MEDIUM N/A
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
CVE-2005-2276 1 Novell 1 Groupwise Webaccess 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.
CVE-2003-0860 1 Php 1 Php 2025-04-03 10.0 HIGH N/A
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.
CVE-1999-0879 2 Bsdi, Caldera 2 Bsd Os, Openlinux 2025-04-03 10.0 HIGH N/A
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
CVE-2003-0494 1 Snitz Communications 1 Snitz Forums 2000 2025-04-03 10.0 HIGH N/A
password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.
CVE-2005-3394 1 Oaboard 1 Oaboard 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.
CVE-2004-1855 1 Mythic Entertainment 1 Dark Age Of Camelot 2025-04-03 5.0 MEDIUM N/A
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
CVE-2001-0966 1 Nudester.org 1 Nudester 2025-04-03 10.0 HIGH N/A
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.
CVE-2006-3427 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.
CVE-2006-3584 1 Jetbox 1 Jetbox Cms 2025-04-03 7.5 HIGH N/A
Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.