Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29814 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4150 1 Broadcom 1 Cleverpath Portal 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors.
CVE-2002-0746 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
CVE-2004-1400 1 Active Server Corner 1 Asp Calendar 2025-04-03 7.5 HIGH N/A
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.
CVE-2000-1028 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.
CVE-2006-2342 1 Ibm 1 Websphere Application Server 2025-04-03 7.5 HIGH N/A
IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
CVE-2004-1139 7 Altlinux, Conectiva, Debian and 4 more 9 Alt Linux, Linux, Debian Linux and 6 more 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
CVE-2005-4197 1 Nortel 1 Ssl Vpn 2025-04-03 7.5 HIGH N/A
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.
CVE-2006-2442 1 Kphone 1 Kphone 2025-04-03 4.6 MEDIUM N/A
kphone 4.2 creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP passwords.
CVE-2006-1433 1 Annuaire 1 Directory 2025-04-03 5.0 MEDIUM N/A
Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.
CVE-2002-0496 1 Southwest 1 Southwest 2025-04-03 5.0 MEDIUM N/A
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
CVE-2001-0847 1 Lotus 1 Domino Web Server 2025-04-03 7.5 HIGH N/A
Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.
CVE-2001-0517 1 Oracle 1 Oracle8i 2025-04-03 5.0 MEDIUM N/A
Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.
CVE-2004-2641 1 Sun 2 Netra 1280, Sun Fire 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.
CVE-2006-1666 1 Arab Portal 1 Arab Portal 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter.
CVE-2004-2228 1 Mozilla 1 Firefox 2025-04-03 7.2 HIGH N/A
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
CVE-2005-1573 1 Darrel Oneil 1 Asp Virtual News Manager 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2004-2415 1 Davenport 1 Davenport 2025-04-03 5.0 MEDIUM N/A
Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks.
CVE-2005-2134 1 Netbsd 1 Netbsd 2025-04-03 2.1 LOW N/A
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
CVE-2005-1058 1 Cisco 1 Ios 2025-04-03 7.5 HIGH N/A
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
CVE-2006-4287 2 Nes Game, Nes System 2 Nes Game, Nes System 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php.