Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29810 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2793 1 Aspsitem 1 Aspsitem 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
CVE-2003-0474 1 Ashley Brown 1 Iweb Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
CVE-2005-0829 1 Php Fusion 1 Php Fusion 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.
CVE-2004-0980 3 Angus Mackay, Debian, Gentoo 3 Ez-ipupdate, Debian Linux, Linux 2025-04-03 10.0 HIGH N/A
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
CVE-2005-4418 1 Vserver 1 Util-vserver 2025-04-03 7.5 HIGH N/A
util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
CVE-2005-0279 1 Jowood Productions 1 Soldner Secret Wars 2025-04-03 5.0 MEDIUM N/A
Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.
CVE-2005-0706 1 Grip 1 Grip 2025-04-03 7.5 HIGH N/A
Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.
CVE-2001-0187 1 Washington University 1 Wu-ftpd 2025-04-03 10.0 HIGH N/A
Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.
CVE-2003-0549 2 Gnome, Redhat 4 Gdm, Enterprise Linux, Kdebase and 1 more 2025-04-03 5.0 MEDIUM N/A
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
CVE-2000-0262 1 Avm 1 Ken 2025-04-03 5.0 MEDIUM N/A
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.
CVE-2001-0962 1 Ibm 2 Websphere Application Server, Websphere Commerce Suite 2025-04-03 7.5 HIGH N/A
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
CVE-2005-3318 1 Jed Wing 1 Chm Lib 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.
CVE-2001-1526 1 Easyscripts 1 Easynews 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.
CVE-2004-0252 1 Typsoft 1 Typsoft Ftp Server 2025-04-03 5.0 MEDIUM N/A
TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.
CVE-2001-1332 1 Easy Software Products 1 Cups 2025-04-03 7.5 HIGH N/A
Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.
CVE-2006-4025 1 Xennobb 1 Xennobb 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.
CVE-2003-1085 1 Thomson 2 Tcm Cable Modem, Tcw Cable Modem 2025-04-03 5.0 MEDIUM N/A
The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.
CVE-1999-1534 1 Knox Software 1 Arkeia 2025-04-03 7.2 HIGH N/A
Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.
CVE-2006-3237 1 Senokian Solutions 1 Enterprise Groupware Systems 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in index.php in Enterprise Groupware System (EGS) 1.2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.
CVE-2005-0621 1 Enlight Software 1 Scrapland 2025-04-03 5.0 MEDIUM N/A
Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.