Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29855 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0308 1 Stefan Holmberg 1 Admentor 2026-04-16 10.0 HIGH N/A
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.
CVE-2001-0007 1 Netscreen 1 Screen Os 2026-04-16 5.0 MEDIUM N/A
Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.
CVE-2006-3173 1 Content\*builder 1 Content\*builder 2026-04-16 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel parameter to (c) modules/archive/overview.inc.php, and the (3) actualModuleDir parameter to (d) modules/forum/showThread.inc.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2005-4796 1 Sun 2 Solaris, Sunos 2026-04-16 3.6 LOW N/A
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
CVE-2005-1586 1 Open Solution 1 Quick.forum 2026-04-16 5.0 MEDIUM N/A
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
CVE-1999-0455 1 Allaire 1 Coldfusion Server 2026-04-16 7.5 HIGH N/A
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
CVE-2006-4014 1 Symantec 1 Brightmail Antispam 2026-04-16 5.0 MEDIUM N/A
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts".
CVE-2001-0499 1 Oracle 1 Oracle8i 2026-04-16 10.0 HIGH N/A
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.
CVE-2002-0773 1 Hosting Controller 1 Hosting Controller 2026-04-16 10.0 HIGH N/A
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.
CVE-2006-0598 1 Stefan Ritt 1 Elog Web Logbook 2026-04-16 7.5 HIGH N/A
Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.
CVE-1999-1031 1 Behold Software 1 Web Page Counter 2026-04-16 5.0 MEDIUM N/A
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.
CVE-2003-0303 1 Oneorzero 1 Oneorzero Helpdesk 2026-04-16 5.0 MEDIUM N/A
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
CVE-1999-1088 1 Hp 1 Hp-ux 2026-04-16 7.2 HIGH N/A
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
CVE-2004-2087 1 Sandsurfer 1 Sandsurfer 2026-04-16 7.5 HIGH N/A
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
CVE-2000-0976 1 Xfree86 Project 1 Xlib 2026-04-16 4.6 MEDIUM N/A
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
CVE-2001-0879 1 Microsoft 4 Sql Server, Windows 2000, Windows Nt and 1 more 2026-04-16 5.0 MEDIUM N/A
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
CVE-2000-0344 1 Linux 1 Linux Kernel 2026-04-16 5.0 MEDIUM N/A
The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.
CVE-1999-1013 1 Ibm 1 Aix 2026-04-16 7.2 HIGH N/A
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
CVE-2000-0304 1 Microsoft 2 Internet Information Server, Internet Information Services 2026-04-16 5.0 MEDIUM N/A
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
CVE-2005-0969 1 Apple 1 Mac Os X 2026-04-16 4.6 MEDIUM N/A
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.