Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29775 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0659 1 Phpbb Group 1 Phpbb 2025-04-03 5.0 MEDIUM N/A
phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.
CVE-2005-1339 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
CVE-2002-0587 1 Aol 1 Aol Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.
CVE-2003-0476 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.
CVE-2006-1706 1 Kansok Communications 1 Shopweezle 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
CVE-2001-0130 1 Lotus 2 Domino R5 Client, Domino R5 Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.
CVE-2000-0306 1 Sco 1 Openserver 2025-04-03 10.0 HIGH N/A
Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.
CVE-2005-1445 1 Sitepanel 1 Sitepanel 2025-04-03 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to (1) delete arbitrary files via the id parameter in a rmattach action to 5.php, or (2) read arbitrary files via the lang parameter to index.php.
CVE-2003-0382 2 Debian, Michael Jennings 2 Debian Linux, Eterm 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.
CVE-2006-4919 1 Siteatschool 1 Siteatschool 2025-04-03 2.6 LOW N/A
Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter.
CVE-2004-1295 1 Uml-utilities 1 Uml-utilities 2025-04-03 2.1 LOW N/A
The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled).
CVE-2005-0487 1 Kayako 1 Esupport 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.
CVE-2002-0030 1 Adobe 2 Acrobat, Acrobat Reader 2025-04-03 4.6 MEDIUM N/A
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
CVE-2002-1725 1 Onlinetools.org 1 Phpimageview 2025-04-03 5.0 MEDIUM N/A
phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.
CVE-2004-1384 1 Phpgroupware 1 Phpgroupware 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.
CVE-2005-4674 1 Complete Php Counter 1 Complete Php Counter 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary SQL commands via the (1) c or (2) s parameter.
CVE-2000-1097 1 Sonicwall 1 Soho Firewall 2025-04-03 5.0 MEDIUM N/A
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.
CVE-2005-2213 1 Mms Ripper 1 Mms Ripper 2025-04-03 7.5 HIGH N/A
Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.
CVE-2005-1595 1 Codethat 1 Shoppingcart 2025-04-03 5.0 MEDIUM N/A
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.
CVE-2003-0518 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 4.6 MEDIUM N/A
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.