Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29836 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1853 1 Moderngigabyte 1 Modernbill 2025-04-03 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.
CVE-2003-1094 1 Bea 1 Weblogic Server 2025-04-03 7.2 HIGH N/A
BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.
CVE-2003-0425 1 Apple 1 Darwin Streaming Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.
CVE-2001-0493 1 Max Feoktistov 1 Small Http Server 2025-04-03 5.0 MEDIUM N/A
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
CVE-2003-1280 1 Eekim 1 Cgihtml 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.
CVE-2002-0657 1 Openssl 1 Openssl 2025-04-03 7.5 HIGH N/A
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
CVE-1999-0957 1 Great Circle Associates 1 Majorcool 2025-04-03 2.1 LOW N/A
MajorCool mj_key_cache program allows local users to modify files via a symlink attack.
CVE-2004-1425 1 Moodle 1 Moodle 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
CVE-2005-0349 1 Broadcom 1 Brightstor Arcserve Backup 2025-04-03 7.5 HIGH N/A
The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.
CVE-2004-0953 1 Jabber Software Foundation 1 Jabber Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.
CVE-2000-0237 1 Netscape 1 Enterprise Server 2025-04-03 6.4 MEDIUM N/A
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
CVE-2006-2070 1 Mybb 1 Devbb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action.
CVE-2001-1212 1 Aktivate 1 Aktivate 2025-04-03 5.0 MEDIUM N/A
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.
CVE-2002-2162 1 Cerulean Studios 1 Trillian 2025-04-03 4.6 MEDIUM N/A
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.
CVE-2005-3517 1 Chipmunk Scripts 1 Chipmunk Guestbook 2025-04-03 5.0 MEDIUM N/A
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
CVE-2006-2076 1 Pdnsd 1 Pdnsd 2025-04-03 5.0 MEDIUM N/A
Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote attackers to cause a denial of service (memory consumption) via a DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated by the OUSPG PROTOS DNS test suite.
CVE-2001-0309 1 Redhat 1 Linux 2025-04-03 5.0 MEDIUM N/A
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.
CVE-2005-2865 1 Amember 1 Amember 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) directone.inc.php, (7) authorize_aim.inc.php, (8) beanstream.inc.php, (9) config.inc.php, (10) eprocessingnetwork.inc.php, (11) eway.inc.php, (12) linkpoint.inc.php, (13) logiccommerce.inc.php, (14) netbilling.inc.php, (15) payflow_pro.inc.php, (16) paymentsgateway.inc.php, (17) payos.inc.php, (18) payready.inc.php, or (19) plugnplay.inc.php.
CVE-2002-1147 1 Hp 1 Procurve Switch 4000m 2025-04-03 7.1 HIGH N/A
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.
CVE-2004-0131 1 Gnu 1 Radius 2025-04-03 5.0 MEDIUM N/A
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.