Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29488 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3002 1 Easy Ad-manager 1 Easy Ad-manager 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in details.php in Easy Ad-Manager allows remote attackers to inject arbitrary web script or HTML via the mbid parameter, which is reflected in an error message. NOTE: on 20060829, the vendor notified CVE that this issue has been fixed.
CVE-1999-0355 1 Broadcom 1 Controlit 2025-04-03 5.0 MEDIUM N/A
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
CVE-1999-1502 1 Id Software 1 Quake 2025-04-03 7.5 HIGH N/A
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.
CVE-2005-0899 1 Ibm 1 Os 400 2025-04-03 2.1 LOW N/A
AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.
CVE-2006-1922 1 Sweetphp 1 Totalcalendar 2025-04-03 6.4 MEDIUM N/A
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
CVE-2005-3342 1 Norman Ramsey 1 Noweb 2025-04-03 1.2 LOW N/A
noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
CVE-2006-3474 1 Belchior Foundry 1 Vcard 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3) event_id parameter to (d) search.php.
CVE-2006-2961 1 Aclogic 1 Cesarftp 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2001-1442 1 Isc 1 Inn 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.
CVE-2005-0834 1 Belkin 1 Belkin 54g Wireless Router 2025-04-03 5.0 MEDIUM N/A
Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.
CVE-2004-1818 1 Warpspeed 1 4nalbum Module 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.
CVE-2001-1158 1 Checkpoint 1 Firewall-1 2025-04-03 7.5 HIGH N/A
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
CVE-2006-4616 1 Mailenable 3 Mailenable Enterprise, Mailenable Professional, Mailenable Standard 2025-04-03 5.0 MEDIUM N/A
SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.
CVE-2005-0707 1 Ipswitch 1 Ipswitch Collaboration Suite 2025-04-03 7.2 HIGH N/A
Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command.
CVE-2000-0149 1 Zeus Technologies 1 Zeus Web Server 2025-04-03 5.0 MEDIUM N/A
Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.
CVE-2006-3319 1 Php Icalendar 1 Php Icalendar 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter.
CVE-1999-1550 1 F5 1 Tmos 2025-04-03 5.0 MEDIUM N/A
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
CVE-2004-0462 2025-04-03 2.1 LOW N/A
The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.
CVE-2005-2429 1 Mozilla 1 Firefox 2025-04-03 5.0 MEDIUM N/A
Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.
CVE-1999-0846 1 Deerfield 1 Mdaemon 2025-04-03 5.0 MEDIUM N/A
Denial of service in MDaemon 2.7 via a large number of connection attempts.