Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29804 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1309 1 Sendmail 1 Sendmail 2025-04-03 7.2 HIGH N/A
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
CVE-2005-0915 1 Webmasters-debutants 1 Wd Guestbook 2025-04-03 7.5 HIGH N/A
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
CVE-1999-0238 1 Php 1 Php 2025-04-03 10.0 HIGH N/A
php.cgi allows attackers to read any file on the system.
CVE-2002-0580 1 Workforceroi 1 Xpede 2025-04-03 7.5 HIGH N/A
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.
CVE-2003-0980 1 Freescripts 1 Visitorbook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" parameter from a host with a malicious reverse DNS name, (3) via quote marks or ampersands in other parameters.
CVE-2005-1004 1 Profitcode 1 Payprocart 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.
CVE-2005-3580 1 Qdbm 1 Qdbm 2025-04-03 7.2 HIGH N/A
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
CVE-2005-1031 2 E-xoops, Runcms 2 E-xoops, Runcms 2025-04-03 5.0 MEDIUM N/A
RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.
CVE-2006-1578 1 Index Data Aps 1 Keystone Digital Library Suite 2025-04-03 6.4 MEDIUM N/A
Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.
CVE-2002-1082 1 Visualshapers 1 Ezcontents 2025-04-03 5.0 MEDIUM N/A
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
CVE-2006-1420 1 Arabless 1 Saphplesson 2025-04-03 5.0 MEDIUM N/A
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.
CVE-2006-1882 1 Oracle 1 E-business Suite 2025-04-03 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unknown impact and attack vectors, as identified by Vuln# (1) APPS03 in (a) iProcurement; (2) APPS04 in (b) Oracle Application Object Library; (3) APPS06, (4) APPS07, and (5) APPS08 in (c) Oracle Applications Technology Stack; and (6) APPS11 in (d) Oracle Order Capture.
CVE-2002-0300 1 Gnujsp 1 Gnujsp 2025-04-03 5.0 MEDIUM N/A
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.
CVE-2005-0719 1 Hp 1 Tru64 2025-04-03 2.1 LOW N/A
Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.
CVE-2003-1118 1 University Of California 1 Seti At Home 2025-04-03 7.5 HIGH N/A
Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.
CVE-2003-0861 1 Php 1 Php 2025-04-03 10.0 HIGH N/A
Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.
CVE-2006-0057 1 Microsoft 2 Ie, Internet Explorer 2025-04-03 7.5 HIGH N/A
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.
CVE-2004-1431 1 Joe Lumbroso 1 Jacks Formmail.php 2025-04-03 5.0 MEDIUM N/A
FormMail.php 5.0, and possibly other versions, allows remote attackers to read arbitrary files via a full pathname in the ar_file (auto-reply) parameter.
CVE-1999-0224 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Denial of service in Windows NT messenger service through a long username.
CVE-2003-0895 1 Apple 1 Mac Os X 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).