Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29855 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1092 1 Light Speed Technology 1 Deluxeftp 2026-04-16 7.2 HIGH N/A
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
CVE-2004-1237 3 Linux, Redhat, Suse 4 Linux Kernel, Enterprise Linux, Enterprise Linux Desktop and 1 more 2026-04-16 2.1 LOW N/A
Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.
CVE-2005-3207 1 Oracle 1 Forms 2026-04-16 5.0 MEDIUM N/A
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.
CVE-2005-2499 1 Slocate 1 Slocate 2026-04-16 2.1 LOW N/A
slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.
CVE-2005-1015 1 Mailenable 1 Imapd 2026-04-16 10.0 HIGH N/A
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
CVE-1999-0485 1 Openbsd 1 Openbsd 2026-04-16 2.6 LOW N/A
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
CVE-2005-3576 1 Walla Telesite 1 Walla Telesite 2026-04-16 5.0 MEDIUM N/A
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
CVE-1999-1094 1 Microsoft 1 Internet Explorer 2026-04-16 7.5 HIGH N/A
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."
CVE-2003-0366 1 Lysator 1 Lyskom-server 2026-04-16 5.0 MEDIUM N/A
lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.
CVE-1999-0439 2 Caldera, Procmail 2 Openlinux, Procmail 2026-04-16 7.5 HIGH N/A
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.
CVE-2006-3802 1 Mozilla 3 Firefox, Seamonkey, Thunderbird 2026-04-16 5.8 MEDIUM N/A
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.
CVE-2000-1236 1 Oracle 1 Application Server 2026-04-16 7.5 HIGH N/A
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
CVE-2005-0930 1 Chatness 1 Chatness 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.
CVE-2006-1324 1 Woltlab 1 Burning Board 2026-04-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
CVE-2005-0347 1 Realnetworks 1 Realarcade 2026-04-16 5.1 MEDIUM N/A
Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.
CVE-2005-4681 1 Khaled Mardam-bey 1 Mirc 2026-04-16 4.6 MEDIUM N/A
Buffer overflow in mIRC 5.91, 6.03, 6.12, and 6.16 allows local users to execute arbitrary code via a long string that is entered after reaching the DCC Get Folder Dialog. NOTE: this issue has been disputed by the vendor, saying "as far as I can tell, this is neither an exploit nor a vulnerability. The above report describes a local bug in mIRC." It could be that this is only exploitable by the user of the application, and thus would not cross privilege boundaries unless under an otherwise restrictive environment such as a kiosk
CVE-2005-3328 1 Punbb 1 Punbb 2026-04-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.
CVE-2006-1065 1 Mybulletinboard 1 Mybulletinboard 2026-04-16 5.0 MEDIUM N/A
SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.
CVE-2006-2366 1 Openobex 1 Openobex 2026-04-16 2.6 LOW N/A
ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Transfer session.
CVE-2001-0012 1 Isc 1 Bind 2026-04-16 5.0 MEDIUM N/A
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.