Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29511 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1622 1 Ibm 1 Aix 2025-04-03 7.5 HIGH N/A
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
CVE-2002-0486 1 Workforceroi 1 Xpede 2025-04-03 7.2 HIGH N/A
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.
CVE-2006-1712 1 Gnu 1 Mailman 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
CVE-1999-0065 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
CVE-2001-1542 1 Network Associates 1 Webshield Smtp 2025-04-03 7.5 HIGH N/A
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.
CVE-2004-1343 1 Cvs 1 Cvs 2025-04-03 5.0 MEDIUM N/A
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).
CVE-2005-0607 1 Devellion 1 Cubecart 2025-04-03 5.0 MEDIUM N/A
CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.
CVE-1999-0930 1 Matt Wright 1 Wwwboard 2025-04-03 5.0 MEDIUM N/A
wwwboard allows a remote attacker to delete message board articles via a malformed argument.
CVE-2001-0714 1 Sendmail 1 Sendmail 2025-04-03 2.1 LOW N/A
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.
CVE-2006-2216 1 Devsyn 1 Open Bulletin Board 2025-04-03 5.0 MEDIUM N/A
Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.
CVE-2002-0351 1 Matt Blaze 1 Cfs 2025-04-03 7.5 HIGH N/A
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2006-0543 1 Cerulean Studios 1 Trillian 2025-04-03 5.0 MEDIUM N/A
Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4) \'d4, and (5) \'d5. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-1885 1 Yapig 1 Yapig 2025-04-03 5.0 MEDIUM N/A
view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.
CVE-2004-0054 1 Cisco 1 Ios 2025-04-03 7.5 HIGH N/A
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
CVE-2003-0082 1 Mit 2 Kerberos, Kerberos 5 2025-04-03 5.0 MEDIUM N/A
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").
CVE-2004-0047 1 Yamamoto Hirotaka 1 Trr19 2025-04-03 4.6 MEDIUM N/A
Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.
CVE-2006-1709 1 Interaktiv 1 Interaktiv.shop 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in shop_main.cgi in interaktiv.shop 5 allows remote attackers to inject arbitrary web script or HTML via the (1) pn and (2) sbeg parameters.
CVE-2006-2837 1 Techno Dreams 1 Techno Dreams Guest Book 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the "Sign Our GuestBook" page, probably the x_Comments parameter to guestbookadd.asp.
CVE-1999-0078 10 Bsdi, Freebsd, Hp and 7 more 11 Bsd Os, Freebsd, Hp-ux and 8 more 2025-04-03 1.9 LOW N/A
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
CVE-2001-0296 1 Texas Imperial Software 1 Wftpd Pro 2025-04-03 10.0 HIGH N/A
Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.