Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29575 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1055 1 Linux 1 Linux Kernel 2025-04-03 4.9 MEDIUM N/A
The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.
CVE-2002-1123 1 Microsoft 2 Data Engine, Sql Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
CVE-1999-1022 1 Sgi 1 Irix 2025-04-03 6.2 MEDIUM N/A
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
CVE-2003-0061 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
CVE-2006-2947 1 Dmx Forum 1 Dmx Forum 2025-04-03 5.0 MEDIUM N/A
Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter.
CVE-2004-0295 1 Transsoft 1 Broker Ftp Server 2025-04-03 5.0 MEDIUM N/A
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.
CVE-2000-1030 1 Csandt 1 Corporatetime For The Web 2025-04-03 5.0 MEDIUM N/A
CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
CVE-2005-1430 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 3.6 LOW N/A
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
CVE-2003-0209 2 Smoothwall, Sourcefire 2 Smoothwall, Snort 2025-04-03 10.0 HIGH N/A
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.
CVE-1999-1244 1 Darren Reed 1 Ipfilter 2025-04-03 7.2 HIGH N/A
IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.
CVE-2004-1761 1 Ethereal Group 1 Ethereal 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.
CVE-2002-0961 1 Voxel 1 Cbms 2025-04-03 7.5 HIGH N/A
Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.
CVE-2004-2427 1 Axis 14 2100 Network Camera, 2110 Network Camera, 2120 Network Camera and 11 more 2025-04-03 10.0 HIGH N/A
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6) factorydefault.cgi, or (7) cause a denial of service (reboot) via restart.cgi.
CVE-2000-0362 1 Suse 1 Suse Linux 2025-04-03 7.2 HIGH N/A
Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.
CVE-2006-0296 1 Mozilla 2 Firefox, Seamonkey 2025-04-03 5.0 MEDIUM N/A
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
CVE-2002-1470 1 Nullsoft 1 Shoutcast Server 2025-04-03 2.1 LOW N/A
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.
CVE-2006-0892 1 Nocc 1 Nocc 2025-04-03 7.5 HIGH N/A
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.
CVE-2006-3265 1 Qdig 1 Qdig 2025-04-03 2.6 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Qdig before 1.2.9.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pre_gallery or (2) post_gallery parameters.
CVE-2000-0473 1 Analogx 1 Simpleserver Www 2025-04-03 7.5 HIGH N/A
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.
CVE-2005-2074 1 Php Fusion 1 Php Fusion 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.