Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29832 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1566 1 Silent-storm 1 Silent-storm Portal 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.
CVE-2002-0783 1 Opera Software 1 Opera Web Browser 2025-04-03 7.5 HIGH N/A
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL.
CVE-2005-4407 1 Tmc Visionpool 1 Mercury Cms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.
CVE-2005-2728 1 Apache 1 Http Server 2025-04-03 5.0 MEDIUM N/A
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
CVE-2001-1199 1 Steve Kneizys 1 Agora.cgi 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.
CVE-1999-0938 1 University College London 1 Sdr 2025-04-03 7.5 HIGH N/A
MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages.
CVE-2005-0330 1 People Can Fly 1 Painkiller 2025-04-03 2.1 LOW N/A
Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.
CVE-2006-4242 1 Joomla 1 Jim Instant Messaging Component 2025-04-03 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
CVE-2005-3917 1 Commodityrentals 1 Commodityrentals 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2003-0876 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 2.1 LOW N/A
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.
CVE-2002-0747 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Buffer overflow in lsmcode in AIX 4.3.3.
CVE-2005-0488 3 Microsoft, Mit, Sun 3 Telnet Client, Kerberos 5, Sunos 2025-04-03 5.0 MEDIUM N/A
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
CVE-2002-0176 1 Avaya 1 Libsafe 2025-04-03 4.6 MEDIUM N/A
The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe.
CVE-2001-0770 1 Steve Poulsen 1 Guildftpd 2025-04-03 7.5 HIGH N/A
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.
CVE-2005-4014 1 Php Web 1 Statistik 2025-04-03 7.8 HIGH N/A
stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large lastnumber value.
CVE-2000-0363 1 Suse 1 Suse Linux 2025-04-03 6.2 MEDIUM N/A
Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.
CVE-2005-2327 1 E107 1 E107 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.
CVE-2005-1317 1 Horde 1 Chora 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2002-1446 1 Ncipher 1 Pkcs 11 Library 2025-04-03 5.0 MEDIUM N/A
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
CVE-2006-0211 1 Helm Hosting 1 Helm Hosting Control Panel 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.