Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0094 1 Freebsd 1 Freebsd 2025-04-03 7.2 HIGH N/A
Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.
CVE-2006-3542 1 Boxcar Media 1 Shopping Cart 2025-04-03 5.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php.
CVE-2005-3508 1 Galerie 1 Galerie 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.
CVE-1999-0213 1 Sun 2 Solaris, Sunos 2025-04-03 10.0 HIGH N/A
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
CVE-2005-0094 1 Squid 1 Squid 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
CVE-2005-3213 1 Frisk Software 1 F-prot Antivirus 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in unspecified versions of F-Prot Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
CVE-2003-0231 1 Microsoft 2 Data Engine, Sql Server 2025-04-03 5.0 MEDIUM N/A
Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
CVE-2004-1391 1 Qnx 2 Rtos, Rtp 2025-04-03 4.6 MEDIUM N/A
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
CVE-2005-4723 2 D-link, Dlink 4 Di-524, Di-784, Di-524 and 1 more 2025-04-03 5.0 MEDIUM N/A
D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.
CVE-2000-0587 1 Glftpd 1 Glftpd 2025-04-03 10.0 HIGH N/A
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.
CVE-2006-2825 1 Cpanel 1 Cpanel 2025-04-03 5.1 MEDIUM N/A
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.
CVE-2000-0639 1 Sean Macguire 1 Big Brother 2025-04-03 7.5 HIGH N/A
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.
CVE-2004-2458 1 Open Webmail 1 Open Webmail 2025-04-03 5.0 MEDIUM N/A
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
CVE-2003-0326 1 Slocate 1 Slocate 2025-04-03 4.6 MEDIUM N/A
Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.
CVE-2005-3492 1 Johannes F. Kuhlmann 1 Flatfrag 2025-04-03 5.0 MEDIUM N/A
FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference.
CVE-2006-4417 1 Xoops 1 Xoops 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avatar parameter.
CVE-2004-0013 1 Jabber Software Foundation 1 Jabber Server 2025-04-03 5.0 MEDIUM N/A
jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).
CVE-2006-1070 1 Dvguestbook 1 Dvguestbook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.
CVE-1999-0717 1 Microsoft 5 Excel, Windows 2000, Windows 95 and 2 more 2025-04-03 2.6 LOW N/A
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
CVE-2006-0571 1 Hinton Design 1 Phpstatus 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.