Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29560 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1685 1 Smc Networks 2 Smc7004vwbr, Smc7008abr 2025-04-03 7.5 HIGH N/A
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.
CVE-2005-2453 1 Networkactiv 1 Networkactiv Web Server 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.
CVE-2002-0124 1 Mdg Computer Services 1 Web Server 4d Ecommerce 2025-04-03 5.0 MEDIUM N/A
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
CVE-2000-0044 1 Jgaa 1 Warftpd 2025-04-03 10.0 HIGH N/A
Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.
CVE-2006-0572 1 Hinton Design 1 Phpstatus 2025-04-03 7.5 HIGH N/A
phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication.
CVE-2004-1792 1 Yatsoft 1 Switch Off 2025-04-03 5.0 MEDIUM N/A
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).
CVE-2002-1490 1 Netbsd 1 Netbsd 2025-04-03 2.1 LOW N/A
NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and sets the counter to zero, which frees memory that is still in use by other processes.
CVE-2003-0832 1 Webfs 1 Webfs 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.
CVE-2005-2916 1 Linksys 1 Wrt54g 2025-04-03 5.0 MEDIUM N/A
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.
CVE-2003-0404 1 Vignette 3 Content Suite, Storyserver, Vignette 2025-04-03 4.3 MEDIUM N/A
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.
CVE-2005-0535 2 Gentoo, Mediawiki 2 Linux, Mediawiki 2025-04-03 7.5 HIGH N/A
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
CVE-2003-0740 1 Stunnel 1 Stunnel 2025-04-03 4.6 MEDIUM N/A
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.
CVE-2003-0615 3 Cgi.pm, Debian, Openpkg 3 Cgi.pm, Debian Linux, Openpkg 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
CVE-2004-0126 1 Freebsd 1 Freebsd 2025-04-03 4.6 MEDIUM N/A
The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.
CVE-2006-3781 1 Sun 1 Solaris 2025-04-03 7.8 HIGH N/A
Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.
CVE-2006-0184 1 Mainenet Enterprises 1 Asptopsites 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.
CVE-2006-3093 1 Adobe 1 Acrobat Reader 2025-04-03 6.8 MEDIUM N/A
Multiple unspecified vulnerabilities in Adobe Acrobat Reader (acroread) before 7.0.8 have unknown impact and unknown vectors.
CVE-2002-0110 1 Nevrona Designs 1 Miramail 2025-04-03 2.1 LOW N/A
Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.
CVE-2005-1449 1 S9y 1 Serendipity 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.
CVE-2006-1156 1 Manas Tungare 1 Site Membership Script 2025-04-03 5.0 MEDIUM N/A
SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp.