Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29798 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1480 1 Raiden Professional Servers 1 Raidenftpd 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command.
CVE-2001-0148 1 Microsoft 1 Windows Media Player 2025-04-03 7.5 HIGH N/A
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.
CVE-1999-1030 1 Behold Software 1 Web Page Counter 2025-04-03 5.0 MEDIUM N/A
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
CVE-2005-4035 1 Web4future 1 Web4future Ecommerce 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
CVE-2001-0970 1 Tdavid 1 Td Forum 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.
CVE-2005-0275 1 3com 1 3cdaemon 2025-04-03 5.0 MEDIUM N/A
TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.
CVE-2004-2628 1 Acme Labs 1 Thttpd 2025-04-03 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
CVE-1999-1306 1 Cisco 1 Ios 2025-04-03 7.5 HIGH N/A
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
CVE-2000-0609 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 5.0 MEDIUM N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
CVE-2003-0954 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
CVE-2006-0632 1 Phpbb Group 1 Phpbb 2025-04-03 6.4 MEDIUM N/A
The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.
CVE-1999-0887 1 Floosietek 1 Ftgate 2025-04-03 5.0 MEDIUM N/A
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
CVE-2003-0115 1 Microsoft 2 Ie, Internet Explorer 2025-04-03 7.5 HIGH N/A
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.
CVE-2003-0350 1 Microsoft 1 Windows 2000 2025-04-03 4.6 MEDIUM N/A
The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.
CVE-2005-1212 1 Microsoft 7 Windows 2000, Windows 2000 Terminal Services, Windows 2003 Server and 4 more 2025-04-03 7.5 HIGH N/A
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
CVE-2005-4484 1 Iatek 1 Intranetapp 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.
CVE-2005-4586 1 Phpsurveyor 1 Phpsurveyor 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, (3) lid, (4) gid, and (5) token parameters in certain PHP scripts.
CVE-2005-4858 1 Chitta 1 Mimicboard 2 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters associated with the (1) name, (2) title, and (3) comment sections, as demonstrated by referencing a remote document through the SRC attribute of an IFRAME element.
CVE-1999-1045 1 Realnetworks 1 Realserver 2025-04-03 7.8 HIGH N/A
pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
CVE-2003-1476 1 Cerberus 1 Ftp Server 2025-04-03 2.1 LOW N/A
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.