Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29560 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4670 1 Citypost 1 Php Lnkx 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
CVE-2005-0762 1 Imagemagick 1 Imagemagick 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.
CVE-2005-2871 1 Mozilla 1 Firefox 2025-04-03 7.5 HIGH N/A
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.
CVE-2003-1194 1 Booby 1 Booby 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.
CVE-2004-0873 1 Apple 2 Ichat, Ichat Av 2025-04-03 7.5 HIGH N/A
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
CVE-2005-4446 1 Aspbite 1 Aspbite 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.
CVE-2006-4669 1 Somery 1 Somery 2025-04-03 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.
CVE-2005-1700 1 Postnuke Software Foundation 1 Postnuke 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.
CVE-2006-2044 1 Ip3 Networks 1 Ip3 Netaccess 75 2025-04-03 7.5 HIGH N/A
na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has a default username of admin and a default password of admin.
CVE-2001-0565 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
CVE-1999-0383 1 Acc 1 Tigris 2025-04-03 7.5 HIGH N/A
ACC Tigris allows public access without a login.
CVE-2003-0553 1 Netscape 1 Navigator 2025-04-03 7.5 HIGH N/A
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
CVE-1999-0791 1 Hybrid Network 2 Cable Modem, Hsmp 2025-04-03 10.0 HIGH N/A
Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.
CVE-2002-2164 1 Microsoft 1 Outlook Express 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
CVE-2004-0432 3 Gentoo, Proftpd Project, Trustix 3 Linux, Proftpd, Secure Linux 2025-04-03 7.5 HIGH N/A
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
CVE-2006-1542 1 Python 1 Python 2025-04-03 3.7 LOW N/A
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.
CVE-2006-3548 1 Horde 1 Horde 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 allow remote attackers to inject arbitrary web script or HTML via a (1) javascript URI or an external (2) http, (3) https, or (4) ftp URI in the url parameter in services/go.php (aka the dereferrer), (5) a javascript URI in the module parameter in services/help (aka the help viewer), and (6) the name parameter in services/problem.php (aka the problem reporting screen).
CVE-2006-2081 1 Oracle 1 Database Server 2025-04-03 4.6 MEDIUM N/A
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue. Based on details of the problem, the primary issue appears to be insecure privileges that facilitate the introduction of SQL in a way that is not related to special characters, so this is not "SQL injection" per se.
CVE-2005-0277 1 3com 1 3cdaemon 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.
CVE-1999-0464 1 Tripwire 1 Tripwire 2025-04-03 2.1 LOW N/A
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.