Total
29562 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1194 | 1 Netbsd | 1 Netbsd | 2025-04-03 | 7.5 HIGH | N/A |
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message. | |||||
CVE-2001-0335 | 1 Microsoft | 1 Internet Information Server | 2025-04-03 | 5.0 MEDIUM | N/A |
FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. | |||||
CVE-2004-0371 | 1 Kth | 1 Heimdal | 2025-04-03 | 5.0 MEDIUM | N/A |
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path. | |||||
CVE-2006-1599 | 1 V-creator.com | 1 V-creator | 2025-04-03 | 7.5 HIGH | N/A |
Unspecified vulnerability in VCEngine.php in v-creator before 1.3-pre3, when the VC_CRYPTO_METHOD option is OPENSSL, allows remote attackers to execute arbitrary commands, possibly due to problems in the (1) encrypt and (2) decrypt functions. | |||||
CVE-2002-0798 | 1 Hp | 1 Hp-ux | 2025-04-03 | 2.1 LOW | N/A |
Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service. | |||||
CVE-2005-0941 | 1 Openoffice | 1 Openoffice | 2025-04-03 | 5.1 MEDIUM | N/A |
The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow. | |||||
CVE-2006-4217 | 1 Webinsta | 1 Webinsta Cms | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2003-0335 | 1 Slackware | 1 Slackware Linux | 2025-04-03 | 7.5 HIGH | N/A |
rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec. | |||||
CVE-2004-2007 | 1 Adam Webb | 1 Nukejokes | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function. | |||||
CVE-2000-0701 | 3 Conectiva, Gnu, Redhat | 3 Linux, Mailman, Linux | 2025-04-03 | 4.6 MEDIUM | N/A |
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges. | |||||
CVE-2005-4064 | 1 Alan Ward | 1 A-faq | 2025-04-03 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp. | |||||
CVE-2001-0349 | 1 Microsoft | 1 Windows 2000 | 2025-04-03 | 7.2 HIGH | N/A |
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability. | |||||
CVE-2000-0772 | 1 Tumbleweed | 1 Messaging Management System | 2025-04-03 | 7.5 HIGH | N/A |
The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. | |||||
CVE-2005-2208 | 1 Privashare | 1 Privashare | 2025-04-03 | 5.0 MEDIUM | N/A |
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message. | |||||
CVE-2002-0262 | 1 Sybex | 1 E-trainer | 2025-04-03 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2006-2450 | 1 Libvncserver | 1 Libvncserver | 2025-04-03 | 7.5 HIGH | N/A |
auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369. | |||||
CVE-2005-2866 | 1 Mercora | 1 Imradio | 2025-04-03 | 4.6 MEDIUM | N/A |
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which allows local users to gain privileges. | |||||
CVE-1999-0260 | 1 Renaud Deraison | 1 Jj | 2025-04-03 | 7.5 HIGH | N/A |
The jj CGI program allows command execution via shell metacharacters. | |||||
CVE-1999-1215 | 1 Novell | 1 Netware | 2025-04-03 | 4.6 MEDIUM | N/A |
LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges. | |||||
CVE-2005-2562 | 1 Gravity Board X Development Team | 1 Gravity Board X | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field. |