Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1450 1 Ibm 1 U2 Universe 2025-04-03 5.0 MEDIUM N/A
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.
CVE-2005-4057 1 Jonathan Beckett 1 Pluggedout Nexus 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters.
CVE-2005-0502 1 Xinkaa Web Station 1 Xinkaa Web Station 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.
CVE-2003-0249 1 Php 1 Php 2025-04-03 7.5 HIGH N/A
PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.
CVE-2006-1327 1 Softbb 1 Softbb 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in reg.php in SoftBB 0.1 allows remote attackers to execute arbitrary SQL commands via the mail parameter.
CVE-2005-0346 1 Safenet 1 Softremote Vpn Client 2025-04-03 2.1 LOW N/A
SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.
CVE-2006-4246 1 Usermin 1 Usermin 2025-04-03 3.6 LOW N/A
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.
CVE-2003-0073 1 Oracle 1 Mysql 2025-04-03 5.0 MEDIUM N/A
Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.
CVE-2003-0198 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 6.4 MEDIUM N/A
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
CVE-2005-3098 1 Qualcomm 1 Qpopper 2025-04-03 4.6 MEDIUM N/A
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.
CVE-2004-0726 1 Microsoft 1 Windows 2000 2025-04-03 7.5 HIGH N/A
The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
CVE-2000-0566 3 Caldera, Mandrakesoft, Redhat 3 Openlinux, Mandrake Linux, Linux 2025-04-03 7.2 HIGH N/A
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
CVE-2006-4617 1 Vtiger 1 Vtiger Crm 2025-04-03 7.5 HIGH N/A
Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and execute arbitrary files with executable extensions in the /cashe/mails folder.
CVE-2004-1285 1 Mplayer 1 Mplayer 2025-04-03 10.0 HIGH N/A
Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
CVE-2000-0398 1 Rockliffe 1 Mailsite 2025-04-03 10.0 HIGH N/A
Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.
CVE-2005-2485 1 Logicampus 1 Logicampus 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2001-0430 1 Debian 1 Debian Linux 2025-04-03 3.6 LOW N/A
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.
CVE-2006-4884 1 Idevspot 1 Isupport 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2001-0653 1 Sendmail 1 Sendmail 2025-04-03 4.6 MEDIUM N/A
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.
CVE-2001-1547 1 Microsoft 1 Outlook Express 2025-04-03 7.5 HIGH N/A
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.