Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29798 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0266 1 Bvrp Software 1 Slwebmail 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.
CVE-2006-0785 1 Phpkit 1 Phpkit 2025-04-03 6.4 MEDIUM N/A
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.
CVE-2004-2132 1 Pj Cgi Neo Review 1 Pj Cgi Neo Review 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.
CVE-2006-0083 1 Stefan Frings 1 Sms Server Tools 2025-04-03 4.6 MEDIUM N/A
Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.
CVE-2000-1045 1 Padl Software 1 Nss Ldap 2025-04-03 1.2 LOW N/A
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.
CVE-1999-0508 2025-04-03 4.6 MEDIUM N/A
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
CVE-2006-4380 1 Mysql 1 Mysql 2025-04-03 2.1 LOW N/A
MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.
CVE-2005-0657 1 Computalynx 1 Cproxy 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.
CVE-2001-0777 1 Omnicron 1 Omnihttpd 2025-04-03 5.0 MEDIUM N/A
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.
CVE-2001-1580 2 Nombas, Novell 2 Scriptease Webserver, Netware 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.
CVE-1999-0421 1 Slackware 1 Slackware Linux 2025-04-03 7.2 HIGH N/A
During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.
CVE-2005-0796 1 Hola 1 Holacms 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
CVE-2006-0335 1 Kerio 1 Winroute Firewall 2025-04-03 5.0 MEDIUM N/A
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.
CVE-2006-3195 1 Singapore 1 Singapore 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the template parameter.
CVE-2001-0027 1 Proftpd Project 1 Proftpd 2025-04-03 7.5 HIGH N/A
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.
CVE-2005-4709 1 Jboss 1 Enterprise Java Beans 2025-04-03 5.0 MEDIUM N/A
The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous client who had the same JBoss server thread.
CVE-2005-3595 1 Microsoft 1 Windows Xp 2025-04-03 10.0 HIGH N/A
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.
CVE-2003-0679 1 Sgi 1 Irix 2025-04-03 2.1 LOW N/A
Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.
CVE-2004-2235 1 Moodle 1 Moodle 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
CVE-2005-0581 1 Broadcom 1 License Software 2025-04-03 4.6 MEDIUM N/A
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.