Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29514 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1745 1 Bitweaver 1 Bitweaver 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-0530 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.
CVE-2002-0396 1 Red-m 1 1050ap Lan Acess Point 2025-04-03 7.5 HIGH N/A
The web management server for Red-M 1050 (Bluetooth Access Point) does not use session-based credentials to authenticate users, which allows attackers to connect to the server from the same IP address as a user who has already established a session.
CVE-2005-4266 1 Alt-n 2 Mdaemon, Worldclient 2025-04-03 7.5 HIGH N/A
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
CVE-2002-1628 1 Mike Spice 1 Mikes Vote Cgi 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type parameter.
CVE-2006-3234 1 Looknet 1 Fineshop 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.
CVE-2005-2295 1 Pyrosoft Inc 1 Netpanzer 2025-04-03 5.0 MEDIUM N/A
NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.
CVE-2006-2479 1 Bitrix 1 Bitrix Site Manager 2025-04-03 5.0 MEDIUM N/A
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site.
CVE-2002-1306 1 Kde 1 Kde 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
CVE-2002-2243 1 Akfingerd 1 Akfingerd 2025-04-03 5.0 MEDIUM N/A
Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.
CVE-2000-0942 1 Microsoft 1 Indexing Service 2025-04-03 5.1 MEDIUM N/A
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
CVE-2003-0855 1 Charles Kerr 1 Pan 2025-04-03 7.8 HIGH N/A
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.
CVE-2006-4745 1 Scarybear 1 Pocketexpense Pro 2025-04-03 3.6 LOW N/A
ScaryBear PocketExpense Pro 3.9.1 uses an internally recorded key to protect a data file whose contents are stored in plaintext, which allows local users to disable authentication and access the file by modifying a certain value in the file header.
CVE-2001-1565 1 Apple 1 Mac Os X 2025-04-03 2.1 LOW N/A
Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
CVE-2005-4555 1 Dev 1 Dev Web Management System 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) ENTER_ARTICLE_TITLE, (2) SPECIFY_ZONE, (3) ENTER_ARTICLE_HEADER, and (4) ENTER_ARTICLE_BODY indices in the language array parameter.
CVE-2005-0872 1 Phpbb Group 1 Phpbb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.
CVE-2006-2279 1 Arabless 1 Saphplesson 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and (3) Rate parameters in (b) misc.php.
CVE-2005-2693 1 Cvs 1 Cvs 2025-04-03 4.6 MEDIUM N/A
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
CVE-2005-1109 1 Junkbuster 1 Internet Junkbuster 2025-04-03 7.5 HIGH N/A
The filtering of URLs in JunkBuster before 2.0.2-r3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via heap corruption.
CVE-2005-1942 1 Cisco 1 Catalyst 2025-04-03 7.5 HIGH N/A
Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages.