Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29855 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1095 1 Cisco 3 Secure Access Control Server, Vpn 3000 Concentrator Series Software, Vpn 3002 Hardware Client 2026-04-16 5.0 MEDIUM N/A
Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
CVE-2004-2601 1 Ubertec 1 Help Center Live 2026-04-16 6.4 MEDIUM N/A
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.
CVE-2002-0786 1 Critical Path 1 Injoin Directory Server 2026-04-16 5.0 MEDIUM N/A
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
CVE-2005-1169 1 Mafia 1 Mafia Blog 2026-04-16 7.5 HIGH N/A
Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.
CVE-1999-0793 1 Microsoft 1 Internet Explorer 2026-04-16 2.6 LOW N/A
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
CVE-2002-1399 1 Postgresql 1 Postgresql 2026-04-16 10.0 HIGH N/A
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).
CVE-2006-2891 1 Pixelpost 1 Pixelpost 2026-04-16 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.
CVE-2002-0556 1 Deep Forest Software 1 Quik-serv Webserver 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVE-2001-1112 1 Khamil Landross And Zack Jones 1 Eftp 2026-04-16 7.5 HIGH N/A
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.
CVE-2006-3073 1 Cisco 2 Asa 5500, Vpn 3000 Concentrator Series Software 2026-04-16 2.6 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html and (2) connecterror.html, aka bugid CSCsd81095 (VPN3k) and CSCse48193 (ASA). NOTE: the vendor states that "WebVPN full-network-access mode" is not affected, despite the claims by the original researcher.
CVE-2005-4599 1 Moxiecode 1 Tinymce Compressor Php 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter.
CVE-2006-2703 1 Suse 1 Suse Linux 2026-04-16 5.0 MEDIUM N/A
The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and execute commands via a man-in-the-middle (MITM) attack.
CVE-2001-0709 1 Microsoft 1 Internet Information Server 2026-04-16 5.0 MEDIUM N/A
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.
CVE-1999-0184 1 Isc 1 Bind 2026-04-16 6.4 MEDIUM N/A
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
CVE-2005-1765 1 Linux 1 Linux Kernel 2026-04-16 2.1 LOW N/A
syscall in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform, when running in 32-bit compatibility mode, allows local users to cause a denial of service (kernel hang) via crafted arguments.
CVE-2002-1899 1 Icewarp 1 Web Mail 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter.
CVE-2004-1165 1 Kde 2 Kdelibs, Konqueror 2026-04-16 7.5 HIGH N/A
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
CVE-2006-0998 1 Novell 2 Netware, Open Enterprise Server 2026-04-16 5.0 MEDIUM N/A
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.
CVE-2001-1572 1 Linux 1 Linux Kernel 2026-04-16 7.5 HIGH N/A
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.
CVE-1999-0140 1 Microsoft 1 Windows Nt 2026-04-16 5.0 MEDIUM N/A
Denial of service in RAS/PPTP on NT systems.