Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29560 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0114 1 Omnicron 1 Omnihttpd 2025-04-03 5.0 MEDIUM N/A
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
CVE-1999-0636 2025-04-03 10.0 HIGH N/A
The discard service is running.
CVE-2005-1059 1 Linksys 1 Wet11 2025-04-03 2.1 LOW N/A
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.
CVE-2005-3980 1 Edgewall Software 1 Trac 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.
CVE-2006-2474 1 Cosmoshop 1 Cosmoshop 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.
CVE-2001-0749 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2025-04-03 7.5 HIGH N/A
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.
CVE-2006-0229 1 Wehnus 1 Wehntrust 2025-04-03 2.1 LOW N/A
Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when Wehntrust creates the autostart key.
CVE-2005-2263 1 Mozilla 2 Firefox, Mozilla 2025-04-03 5.0 MEDIUM N/A
The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.
CVE-2006-3419 1 Tor 1 Tor 2025-04-03 5.0 MEDIUM N/A
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
CVE-2002-1319 2 Linux, Trustix 2 Linux Kernel, Secure Linux 2025-04-03 2.1 LOW N/A
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
CVE-2005-1714 1 Netwin 1 Surgemail 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-3156 1 Easyguppy 1 Easyguppy 2025-04-03 4.3 MEDIUM N/A
Directory traversal vulnerability in printfaq.php in EasyGuppy (Guppy for Windows) 4.5.4 and 4.5.5 allows remote attackers to read arbitrary files via ".." sequences in the pg parameter, which is cleansed for XSS but not directory traversal.
CVE-2001-0790 1 Specter 1 Specter Ids 2025-04-03 5.0 MEDIUM N/A
Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts.
CVE-2003-0649 1 Xpcd 1 Xpcd 2025-04-03 7.2 HIGH N/A
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
CVE-1999-0692 2 Cray, Sgi 2 Unicos, Irix 2025-04-03 10.0 HIGH N/A
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
CVE-2005-4475 1 Alkacon 1 Opencms 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
CVE-2006-3818 1 Novell 1 Groupwise Webaccess 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.
CVE-2005-1007 1 Stalker 1 Communigate Pro 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
CVE-2003-0468 2 Conectiva, Wietse Venema 2 Linux, Postfix 2025-04-03 5.0 MEDIUM N/A
Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
CVE-1999-1387 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.