Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29561 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0235 8 Clearswift, F-secure, Rarlab and 5 more 13 Mailsweeper, F-secure Anti-virus, F-secure For Firewalls and 10 more 2025-04-03 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
CVE-2002-2142 1 Bea 2 Weblogic Integration, Weblogic Server 2025-04-03 7.5 HIGH N/A
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.
CVE-2004-1757 1 Bea 1 Weblogic Server 2025-04-03 4.6 MEDIUM N/A
BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.
CVE-2006-2358 1 Web-labs 1 Web-labs Cms 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter and (2) unspecified fields related to e-mail alerts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2002-2166 1 E-zone Media Inc. 1 Fusetalk 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.
CVE-2004-1022 1 Kerio 3 Kerio Mailserver, Serverfirewall, Winroute Firewall 2025-04-03 2.1 LOW N/A
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
CVE-2002-0872 1 L2tpd 1 L2tpd 2025-04-03 7.5 HIGH N/A
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
CVE-2005-1479 1 Jgs-xa 1 Jgs-portal 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-1264 1 Xhawk.net 1 Discussion 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.
CVE-2001-1297 1 Actionpoll 1 Actionpoll 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter.
CVE-2006-3959 1 X-scripts 1 X-statistics 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.
CVE-2005-2034 1 Blue-collar Productions 1 I-gallery 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
CVE-2001-0704 1 Arcadia 1 Arcadia Internet Store 2025-04-03 7.5 HIGH N/A
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.
CVE-1999-0312 1 Hp 1 Hp-ux 2025-04-03 5.0 MEDIUM N/A
HP ypbind allows attackers with root privileges to modify NIS data.
CVE-2005-0813 1 Initial Redirect 1 Initial Redirect Squid Proxy Plug-in 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.
CVE-2005-2039 1 Nanoblogger 1 Nanoblogger 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.
CVE-2005-1699 1 Postnuke Software Foundation 1 Postnuke 2025-04-03 4.0 MEDIUM N/A
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.
CVE-2006-1505 1 Basic Analysis And Security Engine 1 Base 2025-04-03 5.0 MEDIUM N/A
base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".
CVE-2005-3812 1 Freeftpd 1 Freeftpd 2025-04-03 6.8 MEDIUM N/A
freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments.
CVE-2003-0148 1 Mcafee 1 Epolicy Orchestrator 2025-04-03 7.2 HIGH N/A
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.