Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29810 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1544 1 Cooolsoft 1 Personal Ftp Server 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.
CVE-2004-1729 1 Nihuo Software 1 Web Log Analyzer 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
CVE-2003-1086 1 Pmachine 2 Pmachine Free, Pmachine Pro 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.
CVE-1999-1577 1 Microsoft 1 Internet Explorer 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
CVE-2003-0650 1 Gamespy 1 Arcade 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file.
CVE-2006-0781 1 Perlblog 1 Perlblog 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.
CVE-2006-3790 1 Ufo2000 1 Ufo2000 2025-04-03 5.0 MEDIUM N/A
The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read.
CVE-2003-0874 1 Deskpro 1 Deskpro 2025-04-03 5.0 MEDIUM N/A
Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.
CVE-2000-1237 1 Floosietek 1 Ftgate 2025-04-03 5.0 MEDIUM N/A
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.
CVE-1999-0278 1 Microsoft 2 Internet Information Server, Windows Nt 2025-04-03 5.0 MEDIUM N/A
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-2003-0897 1 Microsoft 1 Windows Xp 2025-04-03 4.6 MEDIUM N/A
"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.
CVE-2001-0912 1 Mandrakesoft 1 Mandrake Linux 2025-04-03 7.2 HIGH N/A
Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.
CVE-2005-4420 1 Quicksquare Development 1 Honeycomb Archive Enterprise 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
CVE-2003-0546 1 Redhat 1 Up2date 2025-04-03 7.5 HIGH N/A
up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.
CVE-2001-1264 1 Hp 2 Hp-ux, Vvos 2025-04-03 10.0 HIGH N/A
Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.
CVE-2004-2120 1 Reptile Web Server 1 Reptile Web Server 2025-04-03 5.0 MEDIUM N/A
Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.
CVE-1999-0825 1 Sco 1 Unixware 2025-04-03 3.6 LOW N/A
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
CVE-2006-1627 1 Adobe 1 Acrobat Reader 2025-04-03 7.5 HIGH N/A
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.
CVE-2006-0845 1 Leif M. Wright 1 Web Blog 2025-04-03 6.5 MEDIUM N/A
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
CVE-2005-0383 1 Trend Micro 1 Control Manager 2025-04-03 7.5 HIGH N/A
Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password.