Total
29560 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-4519 | 1 Mantis | 1 Mantis | 2025-04-03 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the manage user page (manage_user_page.php) in Mantis 1.0.0rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prefix and (2) sort parameters to the manage user page (manage_user_page.php), or (3) the sort parameter to view_all_set.php. | |||||
CVE-2002-0932 | 1 Luis Bernardo | 1 Myhelpdesk | 2025-04-03 | 6.4 MEDIUM | N/A |
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog. | |||||
CVE-2001-1413 | 1 Ncompress | 1 Ncompress | 2025-04-03 | 7.5 HIGH | N/A |
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument. | |||||
CVE-2006-3917 | 1 R. Corson | 1 Php Forge | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter. | |||||
CVE-2006-3471 | 1 Microsoft | 1 Ie | 2025-04-03 | 5.0 MEDIUM | N/A |
Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method. | |||||
CVE-2005-3927 | 1 Guppy | 1 Guppy | 2025-04-03 | 6.4 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php. | |||||
CVE-2006-1354 | 1 Freeradius | 1 Freeradius | 2025-04-03 | 7.5 HIGH | N/A |
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module. | |||||
CVE-2000-0020 | 1 Man And Mice | 1 Dns Pro | 2025-04-03 | 5.0 MEDIUM | N/A |
DNS PRO allows remote attackers to conduct a denial of service via a large number of connections. | |||||
CVE-2000-0412 | 1 Napster | 1 Knapster | 2025-04-03 | 7.5 HIGH | N/A |
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file. | |||||
CVE-2000-1064 | 1 Hp | 1 Jetdirect | 2025-04-03 | 5.0 MEDIUM | N/A |
Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service. | |||||
CVE-2002-2141 | 1 Bea | 1 Weblogic Server | 2025-04-03 | 7.5 HIGH | N/A |
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions. | |||||
CVE-2002-1544 | 1 Cooolsoft | 1 Personal Ftp Server | 2025-04-03 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get. | |||||
CVE-2004-1729 | 1 Nihuo Software | 1 Web Log Analyzer | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. | |||||
CVE-2003-1086 | 1 Pmachine | 2 Pmachine Free, Pmachine Pro | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code. | |||||
CVE-1999-1577 | 1 Microsoft | 1 Internet Explorer | 2025-04-03 | 5.1 MEDIUM | N/A |
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. | |||||
CVE-2003-0650 | 1 Gamespy | 1 Arcade | 2025-04-03 | 7.5 HIGH | N/A |
Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file. | |||||
CVE-2006-0781 | 1 Perlblog | 1 Perlblog | 2025-04-03 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter. | |||||
CVE-2006-3790 | 1 Ufo2000 | 1 Ufo2000 | 2025-04-03 | 5.0 MEDIUM | N/A |
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read. | |||||
CVE-2003-0874 | 1 Deskpro | 1 Deskpro | 2025-04-03 | 5.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen. | |||||
CVE-2000-1237 | 1 Floosietek | 1 Ftgate | 2025-04-03 | 5.0 MEDIUM | N/A |
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing. |