Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29798 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2257 1 Phpslash 1 Phpslash 2025-04-03 10.0 HIGH N/A
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.
CVE-2004-2108 1 Quadcomm 1 Q-shop 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.
CVE-2006-2499 1 Xfairguy 1 Codeavalanche News 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
CVE-1999-0092 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
CVE-2001-1422 1 Att 1 Winvnc 2025-04-03 7.5 HIGH N/A
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
CVE-2004-0974 3 Mandrakesoft, Netatalk, Redhat 4 Mandrake Linux, Mandrake Linux Corporate Server, Open Source Apple File Share Protocol Suite and 1 more 2025-04-03 2.1 LOW N/A
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
CVE-2005-1829 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.
CVE-2005-0341 1 Apple 1 Safari 2025-04-03 4.3 MEDIUM N/A
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
CVE-2004-0614 1 Osticket 1 Osticket Sts 2025-04-03 6.4 MEDIUM N/A
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
CVE-2005-0175 1 Squid 1 Squid 2025-04-03 5.0 MEDIUM N/A
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
CVE-2002-0311 1 Caldera 2 Openunix, Unixware 2025-04-03 10.0 HIGH N/A
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.
CVE-2006-4757 1 E107 1 E107 2025-04-03 4.6 MEDIUM N/A
Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."
CVE-2005-2471 1 Netpbm 1 Netpbm 2025-04-03 7.5 HIGH N/A
pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.
CVE-2003-1212 1 Maxwebportal 1 Maxwebportal 2025-04-03 7.5 HIGH N/A
MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.
CVE-2000-0968 1 Valve Software 1 Half-life Dedicated Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.
CVE-2002-0638 3 Hp, Mandrakesoft, Redhat 5 Secure Os, Mandrake Linux, Mandrake Linux Corporate Server and 2 more 2025-04-03 6.2 MEDIUM N/A
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
CVE-2002-1622 1 Ibm 1 Aix 2025-04-03 7.5 HIGH N/A
Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."
CVE-2002-0486 1 Workforceroi 1 Xpede 2025-04-03 7.2 HIGH N/A
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.
CVE-2006-1712 1 Gnu 1 Mailman 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
CVE-1999-0065 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.