Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29514 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0282 1 Codeworx Technologies 1 Dcp-portal 2025-04-03 5.0 MEDIUM N/A
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message.
CVE-2000-0632 1 Lsoft 1 Listserv 2025-04-03 7.5 HIGH N/A
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
CVE-2006-2957 1 Skoom 1 I.list 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2005-1801 1 Nokia 1 9500 2025-04-03 2.6 LOW N/A
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.
CVE-2006-3487 1 Virtuastore 1 Virtuastore 2025-04-03 5.0 MEDIUM N/A
VirtuaStore 2.0 stores sensitive files under the web root with insufficient access control, which allows remote attackers to obtain local database information by directly accessing database/virtuastore.mdb.
CVE-2000-1133 1 Flicks Software 1 Authentix 2025-04-03 5.0 MEDIUM N/A
Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.
CVE-2000-0382 1 Allaire 1 Clustercats 2025-04-03 2.6 LOW N/A
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
CVE-2000-0108 1 Intelligent Vending Systems 1 Intellivend 2025-04-03 7.5 HIGH N/A
The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
CVE-2005-0363 1 Awstats 1 Awstats 2025-04-03 7.5 HIGH N/A
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
CVE-2004-1000 1 Debian 1 Lintian 2025-04-03 2.1 LOW N/A
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.
CVE-2004-2602 1 Ubertec 1 Help Center Live 2025-04-03 6.8 MEDIUM N/A
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
CVE-2001-0791 1 Trend Micro 1 Interscan Viruswall 2025-04-03 5.0 MEDIUM N/A
Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.
CVE-2000-0774 1 Bajie 1 Java Http Server 2025-04-03 5.0 MEDIUM N/A
The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.
CVE-2002-0676 1 Apple 1 Mac Os X 2025-04-03 7.5 HIGH N/A
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.
CVE-2002-1711 1 Basilix 1 Basilix Webmail 2025-04-03 2.1 LOW N/A
BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.
CVE-2006-2531 1 Ipswitch 1 Whatsup 2025-04-03 7.5 HIGH N/A
Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
CVE-2004-0215 2 Avaya, Microsoft 5 Definity One Media Server, Ip600 Media Servers, Modular Messaging Message Storage Server and 2 more 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
CVE-2006-3476 1 Phpwebgallery 1 Phpwebgallery 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
CVE-2006-1717 1 Mybulletinboard 1 Mybulletinboard 2025-04-03 5.1 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.
CVE-2004-1183 1 Libtiff 1 Libtiff 2025-04-03 5.1 MEDIUM N/A
Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.