Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29568 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0149 1 Xboing 1 Xboing 2025-04-03 4.6 MEDIUM N/A
Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.
CVE-2004-0058 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.
CVE-2003-1062 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.
CVE-2006-4598 1 Sslinks 1 Sslinks 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in links.php in ssLinks 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) go parameter and (2) id parameter in a rate action.
CVE-2005-1866 1 Vincent Hor 1 Calendarix Advanced 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.
CVE-2004-2572 1 Amax Information Technologies 1 Magic Winmail Server 2025-04-03 5.0 MEDIUM N/A
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.
CVE-2006-0215 1 Qualityebiz 1 Quality Ppc 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter. NOTE: this issue might be resultant from CVE-2006-0216.
CVE-2000-0072 1 Computer Power Solutions 1 Visual Casel 2025-04-03 4.6 MEDIUM N/A
Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.
CVE-2006-4861 1 Mohammed Mehdi Panjwani 1 Complain Center 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in loginprocess.asp in Mohammed Mehdi Panjwani Complain Center 1 allows remote attackers to execute arbitrary SQL commands via the (1) TxtUser (aka Username) and (2) TxtPass (aka Password) parameters in login.asp.
CVE-2004-1986 2 Coppermine, Francisco Burzi 2 Coppermine Photo Gallery, Php-nuke 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.
CVE-2005-1418 1 Netleaf Limited 1 Notjustbrowsing 2025-04-03 4.6 MEDIUM N/A
NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.
CVE-2003-1034 1 Sap 1 Sap Db 2025-04-03 4.6 MEDIUM N/A
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.
CVE-1999-0489 1 Microsoft 1 Windows Nt 2025-04-03 10.0 HIGH N/A
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
CVE-2006-1109 1 Totalecommerce 1 Totalecommerce 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.
CVE-2000-0909 1 University Of Washington 1 Pine 2025-04-03 7.5 HIGH N/A
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
CVE-2005-1931 1 Goodtech Systems 1 Goodtech Smtp Server 2025-04-03 5.0 MEDIUM N/A
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.
CVE-2005-3766 1 Exponent 1 Exponent 2025-04-03 5.0 MEDIUM N/A
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files.
CVE-2005-3642 1 Ibm 1 Informix Dynamic Database Server 2025-04-03 7.5 HIGH N/A
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.
CVE-2004-1162 2 Gentoo, Scponly 2 Linux, Scponly 2025-04-03 7.5 HIGH N/A
The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.
CVE-2006-3574 1 Hitachi 3 Cosminexus Collaboration Portal, Groupmax Collaboration Portal, Groupmax Collaboration Web Client 2025-04-03 6.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts" via unknown vectors (aka HS06-014-01).