Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0457 1 Linux 1 Linux Kernel 2025-04-03 7.1 HIGH N/A
Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.
CVE-2001-1320 1 Pgp 1 Keyserver 2025-04-03 7.5 HIGH N/A
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2005-0766 1 Ethereal Group 1 Ethereal 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).
CVE-2006-2728 1 Jan Chmelik 1 Photoalbum Bandw 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the pic parameter.
CVE-2006-1817 1 The War Forge 1 Warforge.news 2025-04-03 2.6 LOW N/A
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.
CVE-2006-1394 1 University Of Washington 1 Pubcookie 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.
CVE-2006-1207 1 Sergey Korostel 1 Php Upload Center 2025-04-03 5.0 MEDIUM N/A
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
CVE-2005-1893 1 Flatnuke 1 Flatnuke 2025-04-03 5.0 MEDIUM N/A
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.
CVE-2004-1844 1 Expinion.net 1 Member Management System 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.
CVE-1999-1409 2 Netbsd, Sgi 2 Netbsd, Irix 2025-04-03 2.1 LOW N/A
The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.
CVE-2003-0224 1 Microsoft 1 Internet Information Services 2025-04-03 10.0 HIGH N/A
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
CVE-2001-1495 1 Freshmeat 2 Network Query Tool, Network Query Tool Phpnuke 2025-04-03 7.5 HIGH N/A
network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.
CVE-2005-2732 1 Awstats 1 Awstats 2025-04-03 5.0 MEDIUM N/A
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.
CVE-2006-0108 1 Idea Development Id Oy 1 Timecan Cms 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.
CVE-2001-1033 1 Compaq 2 Tru64, Trucluster 2025-04-03 5.0 MEDIUM N/A
Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state.
CVE-2000-0328 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
CVE-2002-2057 1 Teekai 1 Teekai Forum 2025-04-03 5.0 MEDIUM N/A
TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
CVE-2001-1274 1 Oracle 1 Mysql 2025-04-03 7.5 HIGH N/A
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
CVE-2003-0979 1 Freescripts 1 Visitorbook 2025-04-03 5.0 MEDIUM N/A
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that exceeds the $max_posts variable.
CVE-2004-0705 1 Mozilla 1 Bugzilla 2025-04-03 6.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.