Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1985 1 Microsoft 3 Windows 2000, Windows 2003 Server, Windows Xp 2025-04-03 7.5 HIGH N/A
The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
CVE-2006-1150 1 Teg 1 Tenes Empanadas Graciela 2025-04-03 7.8 HIGH N/A
Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.
CVE-2001-0087 1 Michael Glickman 1 Itetris 2025-04-03 7.2 HIGH N/A
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.
CVE-2006-0377 1 Squirrelmail 1 Squirrelmail 2025-04-03 5.0 MEDIUM N/A
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."
CVE-2005-0691 1 Socialmpn 1 Socialmpn 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.
CVE-2006-0823 1 Geeklog 1 Geeklog 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.
CVE-2005-1675 1 Groove 2 Groove Workspace, Virtual Office 2025-04-03 4.6 MEDIUM N/A
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.
CVE-2005-1038 2 Paul Vixie, Redhat 2 Vixie Cron, Enterprise Linux 2025-04-03 2.1 LOW N/A
crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.
CVE-2005-1221 1 Ecommerce-carts 1 Ecommpro 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.
CVE-1999-1309 1 Sendmail 1 Sendmail 2025-04-03 7.2 HIGH N/A
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
CVE-2005-0915 1 Webmasters-debutants 1 Wd Guestbook 2025-04-03 7.5 HIGH N/A
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
CVE-1999-0238 1 Php 1 Php 2025-04-03 10.0 HIGH N/A
php.cgi allows attackers to read any file on the system.
CVE-2002-0580 1 Workforceroi 1 Xpede 2025-04-03 7.5 HIGH N/A
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.
CVE-2003-0980 1 Freescripts 1 Visitorbook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" parameter from a host with a malicious reverse DNS name, (3) via quote marks or ampersands in other parameters.
CVE-2005-1004 1 Profitcode 1 Payprocart 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.
CVE-2005-3580 1 Qdbm 1 Qdbm 2025-04-03 7.2 HIGH N/A
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
CVE-2005-1031 2 E-xoops, Runcms 2 E-xoops, Runcms 2025-04-03 5.0 MEDIUM N/A
RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.
CVE-2006-1578 1 Index Data Aps 1 Keystone Digital Library Suite 2025-04-03 6.4 MEDIUM N/A
Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.
CVE-2002-1082 1 Visualshapers 1 Ezcontents 2025-04-03 5.0 MEDIUM N/A
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
CVE-2006-1420 1 Arabless 1 Saphplesson 2025-04-03 5.0 MEDIUM N/A
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.