Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0566 1 Ibm 1 Aix 2025-04-03 5.0 MEDIUM N/A
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
CVE-2006-2413 1 Gnunet 1 Gnunet 2025-04-03 5.0 MEDIUM N/A
GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, possibly involving FIONREAD errors.
CVE-2006-3905 1 Mywebland 1 Mybloggie 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote attackers to execute arbitrary SQL commands via the (1) post_id parameter in index.php and (2) search function.
CVE-1999-1201 1 Microsoft 2 Windows 95, Windows 98 2025-04-03 5.0 MEDIUM N/A
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.
CVE-2005-0519 1 Argosoft 1 Ftp Server 2025-04-03 10.0 HIGH N/A
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.
CVE-2000-0019 1 Ipswitch 1 Imail 2025-04-03 2.1 LOW N/A
IMail POP3 daemon uses weak encryption, which allows local users to read files.
CVE-2004-1300 1 Xine 1 Xine-lib 2025-04-03 10.0 HIGH N/A
Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.
CVE-2005-3758 1 Google 2 Mini Search Appliance, Search Appliance 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet.
CVE-2006-0942 1 Pwsphp 1 Pwsphp 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.
CVE-2006-0717 1 Ibm 1 Tivoli Directory Server 2025-04-03 5.0 MEDIUM N/A
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
CVE-2006-4560 1 Microsoft 1 Ie 2025-04-03 7.5 HIGH N/A
Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
CVE-2003-0402 1 Vignette 3 Content Suite, Storyserver, Vignette 2025-04-03 5.0 MEDIUM N/A
The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.
CVE-2004-2336 1 Novell 2 Groupwise, Netware 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
CVE-2001-0013 1 Isc 1 Bind 2025-04-03 10.0 HIGH N/A
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.
CVE-2004-1917 1 Lcdproc 1 Lcdproc 2025-04-03 7.5 HIGH N/A
Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.
CVE-2003-0087 1 National Language Support 1 Libim 2025-04-03 7.2 HIGH N/A
Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.
CVE-1999-0820 1 Freebsd 1 Freebsd 2025-04-03 4.6 MEDIUM N/A
FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.
CVE-2005-3094 1 Avi Alkalay 1 Man Cgi 2025-04-03 7.5 HIGH N/A
Avi Alkalay man-cgi script allows remote attackers to execute arbitrary code via shell metacharacters in the topic parameter.
CVE-2004-0364 1 Symantec 1 Norton Internet Security 2025-04-03 7.5 HIGH N/A
The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.
CVE-2001-1286 1 Ipswitch 1 Imail 2025-04-03 7.5 HIGH N/A
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.