Total
29562 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-3010 | 1 Aliacom | 1 Open Business Management | 2025-04-03 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php, and the (3) entity and (4) tf_dateafter parameter to company/company_index.php. | |||||
CVE-2006-1917 | 1 Blackorpheus | 1 Clanmemberskript | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter. | |||||
CVE-2006-4750 | 1 Openi-cms Group | 1 Openi-cms | 2025-04-03 | 5.1 MEDIUM | N/A |
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter. | |||||
CVE-2005-2958 | 1 Gnome | 1 Libgda2 | 2025-04-03 | 7.5 HIGH | N/A |
Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code. | |||||
CVE-2004-0841 | 2 Avaya, Microsoft | 7 Definity One Media Server, Ip600 Media Servers, Modular Messaging Message Storage Server and 4 more | 2025-04-03 | 5.0 MEDIUM | N/A |
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability." | |||||
CVE-2001-0161 | 1 Cisco | 1 Aironet | 2025-04-03 | 5.0 MEDIUM | N/A |
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. | |||||
CVE-2005-1146 | 1 Calendarscript | 1 Calendarscript | 2025-04-03 | 4.3 MEDIUM | N/A |
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145 | |||||
CVE-1999-1397 | 1 Microsoft | 1 Index Server | 2025-04-03 | 7.5 HIGH | N/A |
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. | |||||
CVE-2005-4443 | 1 Gauche | 1 Gauche | 2025-04-03 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. | |||||
CVE-2002-0358 | 1 Sgi | 1 Mediamail | 2025-04-03 | 4.6 MEDIUM | N/A |
MediaMail and MediaMail Pro in SGI IRIX 6.5.16 and earlier allows local users to force the program to dump core via certain arguments, which could allow the users to read sensitive data or gain privileges. | |||||
CVE-1999-1368 | 1 Broadcom | 1 Inoculateit | 2025-04-03 | 7.5 HIGH | N/A |
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox. | |||||
CVE-2003-1276 | 1 Nettelephone | 1 Nettelephone | 2025-04-03 | 4.6 MEDIUM | N/A |
Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts. | |||||
CVE-2003-0551 | 1 Redhat | 1 Linux | 2025-04-03 | 5.0 MEDIUM | N/A |
The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service. | |||||
CVE-2002-2184 | 1 Digi-net Technologies | 1 Digichat | 2025-04-03 | 5.0 MEDIUM | N/A |
Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet. | |||||
CVE-2001-0164 | 1 Netscape | 1 Directory Server | 2025-04-03 | 7.5 HIGH | N/A |
Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field. | |||||
CVE-2005-1200 | 1 Azbb | 1 Az Bulletin Board | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code. | |||||
CVE-2004-2403 | 1 Yabb | 1 Yabb | 2025-04-03 | 10.0 HIGH | N/A |
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters. | |||||
CVE-1999-1374 | 1 Arpanet | 1 Perlshop | 2025-04-03 | 5.0 MEDIUM | N/A |
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request. | |||||
CVE-2005-0732 | 1 Py Software | 1 Active Webcam | 2025-04-03 | 5.0 MEDIUM | N/A |
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message. | |||||
CVE-2003-0477 | 1 Wzdftpd | 1 Wzdftpd | 2025-04-03 | 5.0 MEDIUM | N/A |
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument. |