Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0683 1 Virtual Hosting Control System 1 Virtual Hosting Control System 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.
CVE-2001-1109 1 Khamil Landross And Zack Jones 1 Eftp 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
CVE-1999-0675 1 Checkpoint 1 Firewall-1 2025-04-03 5.0 MEDIUM N/A
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
CVE-2004-0193 1 Iss 11 Blackice Agent Server, Blackice Pc Protection, Blackice Server Protection and 8 more 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
CVE-2003-0128 1 Ximian 1 Evolution 2025-04-03 5.0 MEDIUM N/A
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.
CVE-1999-0790 1 Netscape 1 Communicator 2025-04-03 2.6 LOW N/A
A remote attacker can read information from a Netscape user's cache via JavaScript.
CVE-2005-1293 1 Storeportal 1 Storeportal 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.
CVE-2005-2014 1 Php Arena 1 Pafaq 2025-04-03 4.6 MEDIUM N/A
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
CVE-2005-2359 1 Freebsd 1 Freebsd 2025-04-03 5.0 MEDIUM N/A
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.
CVE-1999-0668 1 Microsoft 1 Internet Explorer 2025-04-03 5.1 MEDIUM N/A
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
CVE-2005-2093 1 Oracle 1 Application Server 2025-04-03 4.3 MEDIUM N/A
Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
CVE-2003-1007 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.0 MEDIUM N/A
AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.
CVE-2002-1156 1 Apache 1 Http Server 2025-04-03 5.0 MEDIUM N/A
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
CVE-2005-0278 1 3com 1 3cdaemon 2025-04-03 5.0 MEDIUM N/A
The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.
CVE-2006-2018 1 Jelsoft 1 Vbulletin 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.
CVE-2000-0175 1 Sun 1 Staroffice 2025-04-03 10.0 HIGH N/A
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
CVE-2004-2564 1 Sambar 1 Sambar Server 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.
CVE-2006-0372 1 Insane Visions 1 Blogphp 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
CVE-2001-1122 1 Microsoft 1 Windows Nt 2025-04-03 2.1 LOW N/A
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.
CVE-2000-0303 1 Id Software 1 Quake 3 Arena 2025-04-03 6.4 MEDIUM N/A
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.