Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29514 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0836 1 Ibm 1 Db2 Universal Database 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.
CVE-1999-1287 1 Stephen Turner 1 Analog 2025-04-03 5.0 MEDIUM N/A
Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.
CVE-2005-0135 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).
CVE-1999-0378 1 Trend Micro 1 Interscan Viruswall 2025-04-03 5.0 MEDIUM N/A
InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.
CVE-2005-1086 1 An 1 An-httpd 2025-04-03 6.4 MEDIUM N/A
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.
CVE-2006-0932 1 Pear 1 Pear Archive Zip 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.
CVE-2005-3254 1 Nathan Neulinger 1 Cgiwrap 2025-04-03 10.0 HIGH N/A
The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
CVE-2004-0620 1 Jelsoft 1 Vbulletin 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
CVE-2005-2995 1 Bacula 1 Bacula 2025-04-03 3.6 LOW N/A
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.
CVE-2005-2002 1 Mambo 1 Mambo 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.
CVE-2006-3805 1 Mozilla 3 Firefox, Seamonkey, Thunderbird 2025-04-03 7.5 HIGH N/A
The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
CVE-2005-0377 1 Sergey Kiselev 1 Sgallery 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.
CVE-1999-1299 2 Redhat, Slackware 2 Linux, Slackware Linux 2025-04-03 10.0 HIGH N/A
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.
CVE-2005-4020 1 Widget Press 1 Widget Imprint 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in create.php in Widget Imprint 1.0.26 and earlier allows remote attackers to execute arbitrary SQL commands via the product_id parameter.
CVE-2006-4957 1 The Myreview System 1 Myreview 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.
CVE-1999-0135 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
CVE-2006-2695 1 Dgnews 1 Dgnews 2025-04-03 5.1 MEDIUM N/A
admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.
CVE-2005-3093 1 Nokia 2 3210, 7610 2025-04-03 5.0 MEDIUM N/A
Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.
CVE-2004-2405 1 F-secure 4 F-secure Anti-virus, F-secure For Firewalls, F-secure Internet Security and 1 more 2025-04-03 6.4 MEDIUM N/A
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.
CVE-1999-0924 1 Allaire 1 Coldfusion Server 2025-04-03 5.0 MEDIUM N/A
The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.