Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2712 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 5.0 MEDIUM N/A
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
CVE-2001-1055 1 Microsoft 2 Windows 98, Windows 98se 2025-04-03 5.0 MEDIUM N/A
The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.
CVE-2004-2483 1 Kerio 1 Winroute Firewall 2025-04-03 6.4 MEDIUM N/A
Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).
CVE-2000-0048 1 Corel 1 Linux 2025-04-03 7.2 HIGH N/A
get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.
CVE-2001-0372 1 Akopia 1 Akopia Interchange 2025-04-03 10.0 HIGH N/A
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.
CVE-2000-0740 1 Network Associates 1 Net Tools Pki Server 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.
CVE-2001-0496 2 Mandrakesoft, Redhat 2 Mandrake Linux, Linux 2025-04-03 4.6 MEDIUM N/A
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
CVE-2005-0950 1 Faststone 1 4in1 Browser 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.
CVE-1999-0229 1 Microsoft 1 Internet Information Server 2025-04-03 5.0 MEDIUM N/A
Denial of service in Windows NT IIS server using ..\..
CVE-2006-2051 1 Nextage 1 Nextage Shopping Cart 2025-04-03 5.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.
CVE-2002-2156 1 Cerulean Studios 1 Trillian 2025-04-03 7.5 HIGH N/A
Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.
CVE-2005-4158 1 Todd Miller 1 Sudo 2025-04-03 4.6 MEDIUM N/A
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.
CVE-2005-0451 1 Sami 1 Sami Http Server 2025-04-03 5.0 MEDIUM N/A
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
CVE-2002-0436 1 Sun 2 Solaris, Sunos 2025-04-03 10.0 HIGH N/A
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.
CVE-2005-3214 1 Alwil 1 Avast Antivirus 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
CVE-2006-3543 1 Invision Power Services 1 Invision Power Board 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB
CVE-2006-2954 1 Primoris Software 1 Officeflow 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.
CVE-2002-0854 1 Suse 1 Suse Linux 2025-04-03 7.2 HIGH N/A
Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may allow local users to gain privileges.
CVE-1999-0266 1 Roar Smith 1 Info2www 2025-04-03 7.5 HIGH N/A
The info2www CGI script allows remote file access or remote command execution.
CVE-2001-0997 1 Textor Webmasters Ltd. 1 Listrec.pl 2025-04-03 7.5 HIGH N/A
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.