Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29834 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0989 1 Richard Everitt 1 Pileup 2025-04-03 7.2 HIGH N/A
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.
CVE-2006-0575 1 Thibault Godouet 1 Fcron 2025-04-03 5.0 MEDIUM N/A
convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion.
CVE-2000-1110 1 Ibm 1 Net.data 2025-04-03 5.0 MEDIUM N/A
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
CVE-2005-4839 1 Claymore Systems Inc 1 Puretls 2025-04-03 5.0 MEDIUM N/A
PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.
CVE-2002-1292 1 Microsoft 1 Java Virtual Machine 2025-04-03 7.5 HIGH N/A
The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
CVE-2005-0358 2 Emc, Sun 3 Legato Networker, Solstice Backup, Storedge Enterprise Backup Software 2025-04-03 7.5 HIGH N/A
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
CVE-2002-2218 1 Sips 1 Sips 2025-04-03 10.0 HIGH N/A
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gaining privileges or modifying critical configuration, via a CRLF sequence in a key value.
CVE-2002-1688 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button.
CVE-1999-0512 2025-04-03 10.0 HIGH N/A
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
CVE-2001-0623 1 Sendfile 1 Sendfile 2025-04-03 4.6 MEDIUM N/A
sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.
CVE-2004-1950 1 Phpbb Group 1 Phpbb 2025-04-03 5.0 MEDIUM N/A
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
CVE-2005-2244 1 Cisco 1 Call Manager 2025-04-03 5.0 MEDIUM N/A
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.
CVE-2002-0795 1 Freebsd 1 Freebsd 2025-04-03 2.1 LOW N/A
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.
CVE-2006-1226 1 Drupal 1 Drupal 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
CVE-2005-3409 1 Openvpn 2 Openvpn, Openvpn Access Server 2025-04-03 5.0 MEDIUM N/A
OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.
CVE-2003-0948 1 Wireless Tools 1 Wireless Tools 2025-04-03 7.2 HIGH N/A
Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.
CVE-1999-0912 1 Freebsd 1 Freebsd 2025-04-03 2.1 LOW N/A
FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
CVE-2003-0735 1 Phpwebsite 1 Phpwebsite 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
CVE-1999-1395 1 Dec 1 Dec Openvms 2025-04-03 7.2 HIGH N/A
Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.
CVE-2002-1522 1 Cooolsoft 1 Powerftp 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.