Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29838 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0151 1 Microsoft 3 Windows 2000, Windows Nt, Windows Xp 2025-04-03 7.2 HIGH N/A
Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.
CVE-2005-3331 1 Rogers Software Source 1 Mgdiff Patch Viewer 2025-04-03 2.1 LOW N/A
viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2006-4184 1 Smartline 1 Devicelock 2025-04-03 4.9 MEDIUM N/A
SmartLine DeviceLock before 5.73 Build 305 does not properly enforce access control lists (ACL) in raw mode, which allows local users to bypass NTFS controls and obtain sensitive information.
CVE-2006-3250 1 Microsoft 1 Windows Live Messenger 2025-04-03 5.1 MEDIUM N/A
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is imported by the user.
CVE-2006-3669 1 Mercury Messenger 1 Mercury Messenger 2025-04-03 2.1 LOW N/A
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.
CVE-2006-2755 1 Ubbcentral 1 Ubb.threads 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.
CVE-1999-1184 1 Elm Development Group 1 Elm 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.
CVE-2006-0949 1 Raidenhttpd 1 Raidenhttpd 2025-04-03 5.0 MEDIUM N/A
RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters.
CVE-2006-4366 1 Redblog 1 Redblog 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2005-2945 1 Arc 1 Arc 2025-04-03 2.1 LOW N/A
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).
CVE-2006-3000 1 Okscripts 1 Okarticles 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CVE-2003-0690 1 Kde 1 Kde 2025-04-03 10.0 HIGH N/A
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
CVE-2004-1414 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2025-04-03 5.0 MEDIUM N/A
Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.
CVE-2003-1091 1 Apple 1 Quicktime Broadcaster 2025-04-03 7.5 HIGH N/A
Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.
CVE-2003-0744 1 Leafnode 1 Leafnode 2025-04-03 5.0 MEDIUM N/A
The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.
CVE-2004-2233 1 Moodle 1 Moodle 2025-04-03 10.0 HIGH N/A
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
CVE-2005-1328 1 Oneworldstore 1 Oneworldstore 2025-04-03 5.0 MEDIUM N/A
OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.
CVE-2003-0204 1 Kde 1 Kde 2025-04-03 7.5 HIGH N/A
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
CVE-2004-2476 1 Microsoft 1 Internet Explorer 2025-04-03 2.6 LOW N/A
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
CVE-2005-0332 1 Ventia 1 Desknow Mail And Collaboration Server 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.