Total
29560 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-1391 | 1 Qnx | 2 Rtos, Rtp | 2025-04-03 | 4.6 MEDIUM | N/A |
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program. | |||||
CVE-2005-4723 | 2 D-link, Dlink | 4 Di-524, Di-784, Di-524 and 1 more | 2025-04-03 | 5.0 MEDIUM | N/A |
D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment. | |||||
CVE-2000-0587 | 1 Glftpd | 1 Glftpd | 2025-04-03 | 10.0 HIGH | N/A |
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. | |||||
CVE-2006-2825 | 1 Cpanel | 1 Cpanel | 2025-04-03 | 5.1 MEDIUM | N/A |
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive. | |||||
CVE-2000-0639 | 1 Sean Macguire | 1 Big Brother | 2025-04-03 | 7.5 HIGH | N/A |
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server. | |||||
CVE-2004-2458 | 1 Open Webmail | 1 Open Webmail | 2025-04-03 | 5.0 MEDIUM | N/A |
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories. | |||||
CVE-2003-0326 | 1 Slocate | 1 Slocate | 2025-04-03 | 4.6 MEDIUM | N/A |
Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc. | |||||
CVE-2005-3492 | 1 Johannes F. Kuhlmann | 1 Flatfrag | 2025-04-03 | 5.0 MEDIUM | N/A |
FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference. | |||||
CVE-2006-4417 | 1 Xoops | 1 Xoops | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avatar parameter. | |||||
CVE-2004-0013 | 1 Jabber Software Foundation | 1 Jabber Server | 2025-04-03 | 5.0 MEDIUM | N/A |
jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash). | |||||
CVE-2006-1070 | 1 Dvguestbook | 1 Dvguestbook | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter. | |||||
CVE-1999-0717 | 1 Microsoft | 5 Excel, Windows 2000, Windows 95 and 2 more | 2025-04-03 | 2.6 LOW | N/A |
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | |||||
CVE-2006-0571 | 1 Hinton Design | 1 Phpstatus | 2025-04-03 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface. | |||||
CVE-2006-1373 | 1 Php Live | 1 Php Live | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter. | |||||
CVE-2002-1170 | 1 Net-snmp | 1 Net-snmp | 2025-04-03 | 5.0 MEDIUM | N/A |
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference. | |||||
CVE-2005-4788 | 1 Suse | 1 Suse Linux | 2025-04-03 | 2.1 LOW | N/A |
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via "alternate syntax for specifying USB devices." | |||||
CVE-2005-4132 | 1 Contenido | 1 Contendio | 2025-04-03 | 7.5 HIGH | N/A |
Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. NOTE: it is likely that this is a PHP remote file include vulnerability. | |||||
CVE-2006-2188 | 1 Cmscout | 1 Cmscout | 2025-04-03 | 6.8 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Body field of a private message (PM), (2) BBCode, or (3) a forum post. | |||||
CVE-2002-1935 | 1 Pingtel | 1 Xpressa | 2025-04-03 | 5.0 MEDIUM | N/A |
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar. | |||||
CVE-2001-0928 | 1 Gnome | 1 Libgtop Daemon | 2025-04-03 | 7.5 HIGH | N/A |
Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data. |