Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29834 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1999 1 Openttd 1 Openttd 2025-04-03 5.0 MEDIUM N/A
The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.
CVE-2004-0128 1 Phpgedview 1 Phpgedview 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.
CVE-2005-2107 1 Wordpress 1 Wordpress 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
CVE-2005-2820 1 Inter7 1 Sqwebmail 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".
CVE-1999-0459 2025-04-03 4.6 MEDIUM N/A
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.
CVE-2006-0689 1 Scheduling Management.com 1 Time Tracking Software 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
CVE-2006-1565 1 Debian 1 Debian Linux 2025-04-03 4.6 MEDIUM N/A
Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.
CVE-2004-2284 1 Open Webmail 1 Open Webmail 2025-04-03 10.0 HIGH N/A
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
CVE-2003-0613 1 Zblast 1 Zblast 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.
CVE-1999-0579 1 Microsoft 1 Windows Nt 2025-04-03 10.0 HIGH N/A
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
CVE-1999-1266 1 Metamail Corporation 1 Metamail 2025-04-03 5.0 MEDIUM N/A
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.
CVE-2006-0396 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.
CVE-2005-2814 1 Flatnuke 1 Flatnuke 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
CVE-2004-1644 1 Jerod Moemeka 1 Xedus 2025-04-03 5.0 MEDIUM N/A
Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.
CVE-2002-0380 1 Lbl 1 Tcpdump 2025-04-03 7.5 HIGH N/A
Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet.
CVE-2001-1433 1 Cherokee 1 Cherokee Httpd 2025-04-03 7.5 HIGH N/A
Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
CVE-2004-1416 2 Microsoft, Realnetworks 2 Internet Explorer, Realone Player 2025-04-03 5.1 MEDIUM N/A
pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag.
CVE-2002-0712 1 Entrust 1 Entrust Authority Security Manager 2025-04-03 2.1 LOW N/A
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
CVE-2006-4586 1 Tr Forum 1 Tr Forum 2025-04-03 5.5 MEDIUM N/A
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
CVE-1999-0743 1 Debian 1 Debian Linux 2025-04-03 2.1 LOW N/A
Trn allows local users to overwrite other users' files via symlinks.