Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29575 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1869 1 Nival Interactive 2 Etherlords, Etherlords Ii 2025-04-03 5.0 MEDIUM N/A
Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.
CVE-2002-0510 1 Linux 1 Linux Kernel 2025-04-03 5.0 MEDIUM N/A
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.
CVE-2005-0141 1 Mozilla 2 Firefox, Mozilla 2025-04-03 2.6 LOW N/A
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
CVE-2001-0464 1 Crosswind 1 Cyberscheduler 2025-04-03 10.0 HIGH N/A
Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.
CVE-2000-1004 1 Openbsd 1 Openbsd 2025-04-03 4.6 MEDIUM N/A
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
CVE-2005-4174 1 Efiction Project 1 Efiction 2025-04-03 7.5 HIGH N/A
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.
CVE-2000-0990 1 Krzysztof Dabrowski 1 Cmd5checkpw 2025-04-03 7.5 HIGH N/A
cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.
CVE-2006-1971 1 Krankikom 1 Contentboxx 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.
CVE-2003-0021 1 Michael Jennings 1 Eterm 2025-04-03 5.0 MEDIUM N/A
The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.
CVE-2005-0368 1 Chipmunk Scripts 1 Cmscore 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
CVE-2002-0799 1 Youngzsoft 1 Cmailserver 2025-04-03 7.5 HIGH N/A
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.
CVE-2006-2023 1 Ls3 1 Fenice 2025-04-03 5.0 MEDIUM N/A
Integer overflow in the RTSP_msg_len function in rtsp/RTSP_msg_len.c in Fenice 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a large HTTP Content-Length value, which leads to an invalid memory access.
CVE-1999-0101 1 Ibm 1 Aix 2025-04-03 10.0 HIGH N/A
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
CVE-2006-0908 1 Francisco Burzi 1 Php-nuke 2025-04-03 7.5 HIGH N/A
PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.
CVE-1999-1193 1 Next 1 Next 2025-04-03 10.0 HIGH N/A
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
CVE-2002-0126 1 Selom Ofori 1 Blackmoon Ftp Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.
CVE-2004-1902 1 Citrix 1 Metaframe Password Manager 2025-04-03 2.1 LOW N/A
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
CVE-2005-3473 1 Alexander Palmo 1 Simple Php Blog 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
CVE-2002-1158 1 Canna 1 Canna 2025-04-03 7.2 HIGH N/A
Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.
CVE-2005-1358 1 Text.cgi 1 Text.cgi 2025-04-03 7.5 HIGH N/A
text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.