Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1520 1 Intel 1 Xircom Rex 6000 2025-04-03 2.1 LOW N/A
Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.
CVE-2006-3062 1 Myphp Guestbook 1 Myphp Guestbook 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in index.php in myPHP Guestbook 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CVE-2005-3851 1 Onlinetechtools.com 1 Oasys Lite 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.
CVE-2006-0862 1 Infovista 1 Portalse 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL.
CVE-2005-1266 1 Apache 1 Spamassassin 2025-04-03 5.0 MEDIUM N/A
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
CVE-2005-2744 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.
CVE-2006-3132 1 Qto 1 Qtofilemanager 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php.
CVE-2004-1763 1 Haht Commerce 1 Hahtsite Scenario Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project name.
CVE-2005-1491 2 Icewarp, Merak 2 Web Mail, Mail Server 2025-04-03 4.6 MEDIUM N/A
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.
CVE-1999-1487 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.
CVE-2005-1055 1 Towerblog 1 Towerblog 2025-04-03 7.5 HIGH N/A
TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.
CVE-2004-1782 1 David Maciejak 1 Athena Web Registration 2025-04-03 7.5 HIGH N/A
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.
CVE-1999-0166 1 Sun 1 Nfs 2025-04-03 5.0 MEDIUM N/A
NFS allows users to use a "cd .." command to access other directories besides the exported file system.
CVE-2005-0900 1 Nukebookmarks 1 Nukebookmarks 2025-04-03 5.0 MEDIUM N/A
marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
CVE-2005-3513 1 Vubb 1 Vubb 2025-04-03 5.0 MEDIUM N/A
index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').
CVE-2000-0904 1 Qnx 1 Voyager 2025-04-03 5.0 MEDIUM N/A
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.
CVE-2005-1071 1 Jportal 1 Jportal Web Portal 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.
CVE-2005-0890 1 Dream4 1 Koobi Cms 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.
CVE-2003-1023 1 Midnight Commander 1 Midnight Commander 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.
CVE-2006-1504 1 Arab Portal 1 Arab Portal 2025-04-03 5.1 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.