Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29511 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4503 1 Nx5 1 Nx5linx 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in link.php in NX5Linx 1.0 allows remote attackers to read arbitrary files via the logo parameter.
CVE-2006-3357 1 Microsoft 1 Internet Explorer 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
CVE-2002-1027 1 Macromedia 1 Sitespring 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.
CVE-2005-3271 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
Exec in Linux kernel 2.6 does not properly clear posix-timers in multi-threaded environments, which results in a resource leak and could allow a large number of multiple local users to cause a denial of service by using more posix-timers than specified by the quota for a single user.
CVE-2005-1546 1 Ht Editor 1 Ht Editor 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.
CVE-1999-0530 2025-04-03 10.0 HIGH N/A
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
CVE-2005-4550 1 Oracle 1 Application Server Discussion Forum Portlet 2025-04-03 5.0 MEDIUM N/A
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).
CVE-2003-0435 1 Typespeed 1 Typespeed 2025-04-03 7.5 HIGH N/A
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.
CVE-2006-0738 1 Estara 1 Softphone 2025-04-03 5.0 MEDIUM N/A
Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address).
CVE-2005-1577 1 Apg Technology 1 Classmaster 2025-04-03 7.5 HIGH N/A
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.
CVE-2002-1763 1 Sun 1 Sunos 2025-04-03 4.6 MEDIUM N/A
The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.
CVE-2004-2389 1 Jabberstudio 1 Jabber Gadu-gadu Transport 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.
CVE-2005-3150 1 Weex 1 Weex 2025-04-03 7.5 HIGH N/A
Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.
CVE-2006-4061 1 Thomas Pequet 1 Phpprintanalyzer 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the rep_par_rapport_racine variable is initialized before use
CVE-2005-0143 1 Mozilla 2 Firefox, Mozilla 2025-04-03 2.6 LOW N/A
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
CVE-2002-1494 1 Aestiva 1 Html Os 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.
CVE-2003-1143 1 Croteam 1 Serioussam 2025-04-03 7.5 HIGH N/A
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.
CVE-2006-3869 1 Microsoft 1 Ie 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
CVE-2006-1981 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.1 LOW N/A
Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.
CVE-1999-1580 2 Sendmail, Sun 2 Sendmail, Sunos 2025-04-03 7.2 HIGH N/A
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.