Total
29569 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-4922 | 1 Siteatschool | 1 Siteatschool | 2025-04-03 | 5.0 MEDIUM | N/A |
Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions. | |||||
CVE-2005-2082 | 1 Cgi-club | 1 Imtrset | 2025-04-03 | 5.0 MEDIUM | N/A |
im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter. | |||||
CVE-1999-0259 | 1 Infodrom | 1 Cfingerd | 2025-04-03 | 5.0 MEDIUM | N/A |
cfingerd lists all users on a system via search.**@target. | |||||
CVE-1999-0470 | 1 Novell | 1 Netware | 2025-04-03 | 5.0 MEDIUM | N/A |
A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted. | |||||
CVE-2005-1773 | 1 Lsoft | 1 Listserv | 2025-04-03 | 7.5 HIGH | N/A |
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available. | |||||
CVE-2003-1171 | 1 Mod Security | 1 Mod Security | 2025-04-03 | 7.5 HIGH | N/A |
Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data. | |||||
CVE-2003-0669 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | 1.2 LOW | N/A |
Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users. | |||||
CVE-2000-0558 | 1 Hp | 1 Openview Network Node Manager | 2025-04-03 | 10.0 HIGH | N/A |
Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345. | |||||
CVE-2006-2966 | 1 Particle Soft | 1 Particle Wiki | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS protection scheme. | |||||
CVE-2006-3787 | 1 Kerio | 1 Personal Firewall | 2025-04-03 | 2.1 LOW | N/A |
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread. | |||||
CVE-2005-2637 | 1 Phpfreenews | 1 Phpfreenews | 2025-04-03 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php. | |||||
CVE-2006-1011 | 1 Peters Software | 1 Lettermerger | 2025-04-03 | 2.1 LOW | N/A |
LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2002-2223 | 1 Juniper | 2 Netscreen Remote Security Client, Netscreen Remote Vpn Client | 2025-04-03 | 5.1 MEDIUM | N/A |
Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload. | |||||
CVE-2006-2204 | 1 Invision Power Services | 1 Invision Power Board | 2025-04-03 | 5.5 MEDIUM | N/A |
SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. | |||||
CVE-2005-2272 | 1 Apple | 1 Safari | 2025-04-03 | 2.6 LOW | N/A |
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." | |||||
CVE-2006-4123 | 1 Boite De News | 1 Boite De News | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter. | |||||
CVE-2005-2533 | 1 Openvpn | 1 Openvpn | 2025-04-03 | 2.1 LOW | N/A |
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses. | |||||
CVE-2003-1211 | 1 Maxwebportal | 1 Maxwebportal | 2025-04-03 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter. | |||||
CVE-2002-1226 | 1 Kth | 1 Heimdal | 2025-04-03 | 10.0 HIGH | N/A |
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225). | |||||
CVE-2004-0372 | 1 Xine | 1 Xine | 2025-04-03 | 2.1 LOW | N/A |
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts. |