Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29568 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0372 1 Insane Visions 1 Blogphp 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
CVE-2001-1122 1 Microsoft 1 Windows Nt 2025-04-03 2.1 LOW N/A
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.
CVE-2000-0303 1 Id Software 1 Quake 3 Arena 2025-04-03 6.4 MEDIUM N/A
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
CVE-2005-1781 1 Mailenable 2 Mailenable Enterprise, Mailenable Professional 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).
CVE-2005-3565 1 Hp 1 Hp-ux 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.
CVE-2006-4369 1 Integramod 1 Integramod Portal 2025-04-03 2.6 LOW N/A
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter.
CVE-2000-0681 1 Bea 1 Weblogic Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.
CVE-2004-0263 2 Apache, Ibm 2 Http Server, Http Server 2025-04-03 5.0 MEDIUM N/A
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
CVE-2001-0768 1 Steve Poulsen 1 Guildftpd 2025-04-03 4.6 MEDIUM N/A
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.
CVE-2004-2583 1 Smartertools 1 Smartermail 2025-04-03 7.8 HIGH N/A
SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.
CVE-2003-1097 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.
CVE-2003-1331 1 Oracle 1 Mysql 2025-04-03 4.0 MEDIUM N/A
Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
CVE-2006-0584 1 Peoplesoft 1 Peopletools 2025-04-03 2.1 LOW N/A
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.
CVE-2002-0817 1 William Deich 1 Super 2025-04-03 7.2 HIGH N/A
Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.
CVE-2005-3753 1 Linux 1 Linux Kernel 2025-04-03 7.8 HIGH N/A
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be triggered by an attacker.
CVE-2006-3216 1 Clearswift 2 Mailsweeper For Exchange, Mailsweeper For Smtp 2025-04-03 5.0 MEDIUM N/A
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages.
CVE-2005-3704 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).
CVE-2004-2554 1 Novell 1 Client Firewall 2025-04-03 7.2 HIGH N/A
Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.
CVE-2004-2587 1 Smartertools 1 Smartermail 2025-04-03 5.0 MEDIUM N/A
login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow.
CVE-2003-0766 1 Ftp Desktop 1 Ftp Desktop 2025-04-03 7.5 HIGH N/A
Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS command.