Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29568 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0654 1 Apache 1 Http Server 2025-04-03 5.0 MEDIUM N/A
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
CVE-2003-0410 1 Analogx 1 Proxy 2025-04-03 10.0 HIGH N/A
Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.
CVE-2005-3322 2 Squid, Suse 2 Squid, Suse Linux 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
CVE-2004-1362 1 Oracle 9 Application Server, Collaboration Suite, E-business Suite and 6 more 2025-04-03 7.5 HIGH N/A
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
CVE-2000-0293 1 Suse 1 Suse Linux 2025-04-03 2.1 LOW N/A
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.
CVE-2003-0730 2 Netbsd, Xfree86 Project 2 Netbsd, X11r6 2025-04-03 7.5 HIGH N/A
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.
CVE-2001-0067 1 Judd Montgomery 1 Jpilot 2025-04-03 2.1 LOW N/A
The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.
CVE-2004-2279 1 Invision Power Services 1 Invision Power Board 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
CVE-2003-0941 1 Sap 1 Sap Db 2025-04-03 7.5 HIGH N/A
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.
CVE-2006-1541 1 Ezaspsite 1 Ezaspsite 2025-04-03 7.8 HIGH N/A
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.
CVE-2006-0496 1 Mozilla 2 Firefox, Mozilla 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.
CVE-2002-1048 1 Hp 1 Jetdirect 2025-04-03 7.5 HIGH N/A
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.
CVE-2003-0396 1 Linux-atm 1 Linux-atm 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.
CVE-2004-2673 1 Argosoft 1 Ftp Server 2025-04-03 9.0 HIGH N/A
Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument.
CVE-2003-0666 1 Microsoft 1 Wordperfect Converter 2025-04-03 7.5 HIGH N/A
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.
CVE-2006-1425 1 Phpmyfamily 1 Phpmyfamily 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
CVE-2005-3889 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2025-04-03 7.8 HIGH N/A
Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code of 6 or 7, which triggers a large number of popup windows to the user and creates a large number of threads.
CVE-2005-0910 1 E-xoops 1 E-xoops 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat parameter to index.php.
CVE-2000-1082 1 Microsoft 2 Data Engine, Sql Server 2025-04-03 4.6 MEDIUM N/A
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
CVE-1999-1036 1 Cops 1 Cops 2025-04-03 7.2 HIGH N/A
COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.