Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29562 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-0305 1 Okulsistem Okul Web 1 Otomasyon Sistemi 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-1437 2 Ledgersmb, Sql-ledger 2 Ledgersmb, Sql-ledger 2025-04-09 9.0 HIGH N/A
Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.
CVE-2007-4113 1 Advanced Webhost Billing System 1 Advanced Webhost Billing System 2025-04-09 3.5 LOW N/A
Unspecified vulnerability in Advanced Webhost Billing System (AWBS) before 2.6.0 allows remote authenticated users to obtain configuration data about other dedicated servers via unspecified vectors.
CVE-2007-0866 1 Hp 1 Openview Storage Data Protector 2025-04-09 6.8 MEDIUM N/A
Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.
CVE-2007-0006 1 Linux 1 Linux Kernel 2025-04-09 1.9 LOW N/A
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."
CVE-2006-5609 1 Torrentflux 1 Torrentflux 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.
CVE-2007-3449 1 Gorani Network 1 6alblog 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
CVE-2009-3934 1 Google 1 Chrome 2025-04-09 4.3 MEDIUM N/A
The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail.
CVE-2006-5704 1 Hp 1 Nonstop Server 2025-04-09 6.2 MEDIUM N/A
HP NonStop Server G06.29, when running Standard Security T6533G06 before T6533G06^ABK, does not properly evaluate access permissions to OSS directories when no optional ACL entry exists, which allows local users to read arbitrary files.
CVE-2007-1816 1 Xoops 1 Tutoriais Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2007-0227 1 Slocate 1 Slocate 2025-04-09 5.0 MEDIUM N/A
slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files. NOTE: another researcher reports that the issue is not present in slocate 2.7.
CVE-2008-1736 1 Comodo 1 Comodo Personal Firewall 2025-04-09 7.2 HIGH N/A
Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result; and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.
CVE-2007-4437 1 Ampache 1 Ampache 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information.
CVE-2006-7049 1 Wikkawiki 1 Wikkawiki 2025-04-09 7.5 HIGH N/A
The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files.
CVE-2007-0476 1 Gentoo 1 Linux 2025-04-09 4.6 MEDIUM N/A
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.
CVE-2007-0518 1 Scriptsez 1 Smart Php Subscriber 2025-04-09 7.5 HIGH N/A
Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.
CVE-2006-5726 1 Sun 1 Solaris 2025-04-09 4.9 MEDIUM N/A
alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.
CVE-2006-5360 1 Oracle 1 Application Server 2025-04-09 10.0 HIGH N/A
Unspecified vulnerability in Oracle Forms component in Oracle Application Server 9.0.4.2 has unknown impact and remote attack vectors, aka Vuln# FORM03.
CVE-2007-4084 1 Alstrasoft 1 Affiliate Network Pro 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to execute arbitrary SQL commands via (1) the pgmid parameter in an uploadProducts action to merchants/index.php and possibly (2) the rowid parameter to merchants/temp.php.
CVE-2007-2901 1 Dokeos 1 Dokeos 2025-04-09 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.