Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29840 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4614 1 Pocket Pc 1 Pocket Pc 2026-04-16 4.9 MEDIUM N/A
PDAapps Verichat for Pocket PC 1.30bh stores usernames and passwords in plaintext in the Windows Mobile registry, which allows local users to obtain sensitive information via keys under \HKEY_CURRENT_USER\Software\PDAapps\VeriChat.
CVE-2006-1842 1 Cynical Games 1 Shoutbook 2026-04-16 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.
CVE-2005-0289 1 Apple 2 Airport Express, Airport Extreme 2026-04-16 5.0 MEDIUM N/A
Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.
CVE-2006-4485 1 Php 1 Php 2026-04-16 10.0 HIGH N/A
The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.
CVE-2002-0347 1 Sun 3 Cobalt Raq 2, Cobalt Raq 3i, Cobalt Raq 4 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
CVE-2000-0452 1 Lotus 2 Domino Enterprise Server, Domino Mail Server 2026-04-16 5.0 MEDIUM N/A
Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.
CVE-2000-0119 2 Mcafee, Symantec 2 Virusscan, Norton Antivirus 2026-04-16 7.2 HIGH N/A
The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.
CVE-2005-3998 1 Solupress 1 Solupress News 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
CVE-2002-1269 1 Apple 1 Mac Os X 2026-04-16 4.6 MEDIUM N/A
Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.
CVE-2005-3634 1 Sap 1 Sap Web Application Server 2026-04-16 5.0 MEDIUM N/A
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
CVE-2000-0078 1 Hp 1 Hp-ux 2026-04-16 7.2 HIGH N/A
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.
CVE-1999-0632 2026-04-16 N/A N/A
The RPC portmapper service is running.
CVE-2006-3220 1 Woltlab 1 Burning Board 2026-04-16 7.5 HIGH N/A
SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-1999-0028 1 Sgi 1 Irix 2026-04-16 7.2 HIGH N/A
root privileges via buffer overflow in login/scheme command on SGI IRIX systems.
CVE-2000-0512 1 Debian 1 Debian Linux 2026-04-16 5.0 MEDIUM N/A
CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.
CVE-2005-1982 1 Microsoft 3 Windows 2000, Windows 2003 Server, Windows Xp 2026-04-16 3.6 LOW N/A
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
CVE-2006-3971 1 Scott Weedon 1 Ajax Chat 2026-04-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to inject arbitrary web script or HTML via the userid parameter.
CVE-2001-0740 1 3com 2 3c840-us, 3cp4144 2026-04-16 5.0 MEDIUM N/A
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability.
CVE-2003-0175 1 Sgi 1 Irix 2026-04-16 2.1 LOW N/A
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.
CVE-1999-0627 1 Ibm 1 Aix 2026-04-16 N/A N/A
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.