Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0725 1 Zope 1 Zope 2025-04-03 7.2 HIGH N/A
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
CVE-2005-0095 1 Squid 1 Squid 2025-04-03 5.0 MEDIUM N/A
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.
CVE-2002-1009 1 Summit Computer Networks 1 Lil Http Server 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.
CVE-2005-4363 1 Komodo 1 Komodo Cms 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
CVE-2003-0835 1 Mplayer 1 Mplayer 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.
CVE-2003-0251 1 Nis 1 Ypserv Nis Server 2025-04-03 5.0 MEDIUM N/A
ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.
CVE-2005-2891 1 Csystems 1 Webarchivex 2025-04-03 6.4 MEDIUM N/A
WebArchiveX.dll 5.5.0.76 installed before September 6th, 2005 is marked safe for scripting by default, which allows remote attackers to read or write to arbitrary files via the (1) MakeArchive or (2) MakeArchiveStr methods.
CVE-2002-1881 1 Macromedia 1 Flash Player 2025-04-03 5.0 MEDIUM N/A
Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.
CVE-2005-3187 1 Bluecoat 1 Winproxy 2025-04-03 5.0 MEDIUM N/A
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.
CVE-2006-2786 1 Mozilla 2 Firefox, Thunderbird 2025-04-03 2.6 LOW N/A
HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.
CVE-2005-1354 1 Forum.pl 1 Forum.pl 2025-04-03 7.5 HIGH N/A
The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
CVE-2002-0042 1 Sgi 1 Irix 2025-04-03 2.1 LOW N/A
Vulnerability in the XFS file system for SGI IRIX before 6.5.12 allows local users to cause a denial of service (hang) by creating a file that is not properly processed by XFS.
CVE-1999-1448 1 Qualcomm 2 Eudora, Eudora Light 2025-04-03 5.0 MEDIUM N/A
Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.
CVE-2005-4827 2 Canon, Microsoft 3 Network Camera Server Vb101, Ie, Internet Explorer 2025-04-03 7.5 HIGH N/A
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces. NOTE: this issue can be leveraged to conduct referer spoofing, HTTP Request Smuggling, and other attacks.
CVE-1999-0765 1 Sgi 1 Irix 2025-04-03 10.0 HIGH N/A
SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
CVE-2006-4303 1 Sun 1 Solaris 2025-04-03 2.6 LOW N/A
Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers to cause a denial of service ("tight loop" and CPU consumption for listener applications) via unknown vectors related to TCP fusion (do_tcp_fusion).
CVE-1999-1141 1 Ascom 1 Timeplex Routers 2025-04-03 7.5 HIGH N/A
Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.
CVE-2006-2830 1 Tibco 3 Hawk, Rendezvous, Runtime Agent 2025-04-03 7.5 HIGH N/A
Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the HTTP administrative interface.
CVE-1999-1085 1 Ssh 1 Secure Shell 2025-04-03 5.0 MEDIUM N/A
SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."
CVE-2005-4764 1 Bea 1 Weblogic Server 2025-04-03 7.8 HIGH N/A
BEA WebLogic Server and WebLogic Express 9.0, 8.1, and 7.0 lock out the admin user account after multiple incorrect password guesses, which allows remote attackers who know or guess the admin account name to cause a denial of service (blocked admin logins).