Total
29559 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3387 | 1 Luca Deri | 1 Ntop | 2025-04-03 | 4.6 MEDIUM | N/A |
The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code. | |||||
CVE-2005-3788 | 1 Cisco | 1 Adaptive Security Appliance Software | 2025-04-03 | 5.4 MEDIUM | N/A |
Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service." | |||||
CVE-2000-0253 | 1 Craig Dansie | 1 Dansie Shopping Cart | 2025-04-03 | 10.0 HIGH | N/A |
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields. | |||||
CVE-2004-0801 | 4 Conectiva, Linuxprinting.org, Sun and 1 more | 4 Linux, Foomatic-filters, Java Desktop System and 1 more | 2025-04-03 | 7.5 HIGH | N/A |
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands. | |||||
CVE-2004-1908 | 1 Mcafee | 1 Freescan | 2025-04-03 | 5.0 MEDIUM | N/A |
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters. | |||||
CVE-2006-0981 | 1 E-merge | 1 E-merge Winace | 2025-04-03 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | |||||
CVE-2005-2845 | 1 Ariba | 1 Ariba Spend Management Solutions | 2025-04-03 | 5.0 MEDIUM | N/A |
Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information. | |||||
CVE-2004-2563 | 1 Serena Software | 1 Serena Teamtrack | 2025-04-03 | 5.8 MEDIUM | N/A |
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters. | |||||
CVE-2002-1406 | 1 Hp | 1 Hp-ux | 2025-04-03 | 7.2 HIGH | N/A |
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior." | |||||
CVE-2002-2073 | 1 Microsoft | 3 Site Server, Site Server Commerce, Windows Nt | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | |||||
CVE-2005-1946 | 1 Invision Power Services | 1 Invision Community Blog | 2025-04-03 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | |||||
CVE-2005-2617 | 1 Linux | 1 Linux Kernel | 2025-04-03 | 3.6 LOW | N/A |
The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers. | |||||
CVE-2005-3549 | 1 Invision Power Services | 1 Invision Board | 2025-04-03 | 6.5 MEDIUM | N/A |
Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now". | |||||
CVE-1999-0164 | 1 Sun | 1 Sunos | 2025-04-03 | 6.2 MEDIUM | N/A |
A race condition in the Solaris ps command allows an attacker to overwrite critical files. | |||||
CVE-2006-1412 | 1 Tft Gallery | 1 Tft Gallery | 2025-04-03 | 5.0 MEDIUM | N/A |
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd. | |||||
CVE-2006-4504 | 1 Nx5 | 1 Nx5linx | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) c and (2) l parameters. | |||||
CVE-2006-0418 | 1 Topcmm Computing | 1 123 Flash Chat Server | 2025-04-03 | 7.5 HIGH | N/A |
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username. | |||||
CVE-2005-0379 | 1 Zeroboard | 1 Zeroboard | 2025-04-03 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php. | |||||
CVE-2002-1947 | 1 Webmin | 1 Webmin | 2025-04-03 | 6.4 MEDIUM | N/A |
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. | |||||
CVE-2005-3338 | 1 Mantis | 1 Mantis | 2025-04-03 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users. |