Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29511 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1761 1 Blursoft 1 Blur6ex 2025-04-03 2.6 LOW N/A
Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.
CVE-2000-0410 1 Allaire 1 Coldfusion Server 2025-04-03 5.0 MEDIUM N/A
ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.
CVE-1999-0462 1 Suse 1 Suse Linux 2025-04-03 7.2 HIGH N/A
suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.
CVE-2000-0292 1 Adtran 1 Mx2800 2025-04-03 5.0 MEDIUM N/A
The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.
CVE-2005-3306 1 Flatnuke 1 Flatnuke 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307.
CVE-2006-4002 1 Drupal 1 Drupal 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
CVE-2001-0306 1 Itafrica 1 Webactive 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVE-2005-4741 1 Netbsd 1 Netbsd 2025-04-03 7.5 HIGH N/A
NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (P_SUGID) process that performs an exec without a reset of real credentials.
CVE-2001-0258 1 I-data International 1 Easycom Safecom Print Server 2025-04-03 5.0 MEDIUM N/A
The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.
CVE-2002-2217 1 Comscripts 1 Web Server Creator 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php.
CVE-2002-0280 1 Codeblue 1 Codeblue 2025-04-03 7.5 HIGH N/A
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.
CVE-2005-0831 1 Php-post 1 Php-post Web Forum 2025-04-03 5.0 MEDIUM N/A
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
CVE-2000-0339 1 Zonelabs 1 Zonealarm 2025-04-03 7.5 HIGH N/A
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.
CVE-2006-4763 1 Ibm 1 Lotus Domino Web Access 2025-04-03 7.5 HIGH N/A
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.
CVE-2003-0886 1 Hylafax 1 Hylafax 2025-04-03 10.0 HIGH N/A
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
CVE-1999-1591 1 Microsoft 2 Internet Information Server, Visual Interdev 2025-04-03 7.5 HIGH N/A
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
CVE-1999-1252 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.
CVE-1999-1563 1 Nachuatec 2 D435, D445 2025-04-03 5.0 MEDIUM N/A
Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.
CVE-2000-0159 1 Hp 1 Hp-ux 2025-04-03 7.5 HIGH N/A
HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.
CVE-2006-2849 1 Andrew Godwin 1 Bytehoard 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.