Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3002 1 Xclusive-software 1 Mccs 2025-04-03 5.0 MEDIUM N/A
Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet.
CVE-2002-0408 1 Lotus 1 Domino 2025-04-03 5.0 MEDIUM N/A
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.
CVE-2006-2266 1 Chirpy 1 Chirpy 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Chirpy! 0.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
CVE-2001-0515 1 Oracle 2 Database Server, Oracle8i 2025-04-03 5.0 MEDIUM N/A
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
CVE-2002-2022 1 Kaffe 1 Kaffe Openvm 2025-04-03 7.2 HIGH N/A
Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.
CVE-2000-0688 1 Cgi Script Center 1 Subscribe Me Lite 2025-04-03 7.5 HIGH N/A
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.
CVE-2006-2708 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 5.0 MEDIUM N/A
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
CVE-2002-1518 1 Sgi 1 Irix 2025-04-03 3.6 LOW N/A
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.
CVE-2005-4142 1 Lyris Technologies Inc 1 Listmanager 2025-04-03 7.5 HIGH N/A
The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. NOTE: it is not clear whether this is a variant of a CRLF injection vulnerability.
CVE-2001-1031 1 Charles Clark 1 Meteor Ftpd 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command.
CVE-2004-0163 1 Sygate Technologies 1 Secure Enterprise 2025-04-03 5.0 MEDIUM N/A
Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.
CVE-2006-2127 1 Blog Mod 1 Blog Mod 2025-04-03 6.4 MEDIUM N/A
SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter.
CVE-2002-0517 1 Caldera 2 Openunix, Unixware 2025-04-03 7.2 HIGH N/A
Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.
CVE-2006-4917 1 Pt News 1 Pt News 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname parameter.
CVE-2001-1359 1 Caldera 1 Volution 2025-04-03 10.0 HIGH N/A
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.
CVE-2001-0926 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.
CVE-2000-0216 1 Microsoft 3 Exchange Server, Outlook, Windows Messaging 2025-04-03 5.0 MEDIUM N/A
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
CVE-2005-3066 1 Scriptsolutions 1 Perldiver 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.
CVE-2005-0542 1 Cyclades 1 Alterpath Manager 2025-04-03 4.6 MEDIUM N/A
saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.
CVE-2000-0845 1 Digital 1 Unix 2025-04-03 6.4 MEDIUM N/A
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.