Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29810 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0987 1 Apache 1 Http Server 2025-04-03 7.5 HIGH N/A
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
CVE-2006-4114 1 Phpmyring 1 Phpmyring 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.
CVE-2006-1151 1 M Phorum 1 M Phorum 2025-04-03 5.0 MEDIUM N/A
Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.
CVE-2004-1484 1 Socat 1 Socat 2025-04-03 5.0 MEDIUM N/A
Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
CVE-2004-2606 1 Linksys 2 Befsr41 V3, Wrt54g 2025-04-03 7.5 HIGH N/A
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.
CVE-2000-0129 1 Microsoft 3 Windows 95, Windows 98, Windows Nt 2025-04-03 2.1 LOW N/A
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
CVE-2006-3399 1 Moniwiki 1 Moniwiki 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632.
CVE-1999-0661 2025-04-03 10.0 HIGH N/A
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
CVE-2002-2198 1 Zmailer 1 Zmailer 2025-04-03 10.0 HIGH N/A
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
CVE-2006-1996 1 Scry Gallery 1 Scry Gallery 2025-04-03 5.0 MEDIUM N/A
Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.
CVE-2000-0381 1 Gossamer Threads 1 Dbman 2025-04-03 6.4 MEDIUM N/A
The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.
CVE-1999-1527 1 Sun 2 Forte, Netbeans Developer 2025-04-03 7.5 HIGH N/A
Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.
CVE-2004-2676 1 Webroot Software 1 Spy Sweeper Enterprise 2025-04-03 7.2 HIGH N/A
The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges.
CVE-2004-0744 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
CVE-2002-1053 1 W3c 1 Jigsaw 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.
CVE-2001-1135 1 Zyxel 1 Prestige 2025-04-03 7.5 HIGH N/A
ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.
CVE-2006-0437 1 Phpbb Group 1 Phpbb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.
CVE-2000-0039 1 Altavista 1 Search Intranet 2025-04-03 5.0 MEDIUM N/A
AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.
CVE-2004-1948 1 Ncftp Software 1 Ncftp 2025-04-03 4.6 MEDIUM N/A
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
CVE-2000-0483 2 Redhat, Zope 2 Linux Powertools, Zope 2025-04-03 7.5 HIGH N/A
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.