Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0677 1 Phpoutsourcing 1 Zorum 2025-04-03 5.0 MEDIUM N/A
index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.
CVE-2006-3965 1 Banex 1 Banex 2025-04-03 5.0 MEDIUM N/A
Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.
CVE-2006-1851 1 Skymarx Solutions 1 Xflow 2025-04-03 5.0 MEDIUM N/A
xFlow 5.46.11 and earlier allows remote attackers to determine the installation path of the application via the (1) action parameter to members_only/index.cgi and (2) page parameter customer_area/index.cgi, probably due to invalid values.
CVE-2005-2895 1 Pblang 1 Pblang 2025-04-03 5.0 MEDIUM N/A
setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message.
CVE-2002-1501 1 Enterasys 1 Smartswitch Ssr8000 2025-04-03 5.0 MEDIUM N/A
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
CVE-2006-2590 1 E107 1 E107 2025-04-03 6.4 MEDIUM N/A
SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
CVE-2004-2484 1 Php Gift Registry 1 Phpgiftreg 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.
CVE-2005-0712 1 Apple 1 Mac Os X 2025-04-03 4.6 MEDIUM N/A
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
CVE-2005-1082 1 Azerbaijan Development Group 1 Azdgdating 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.
CVE-2005-2460 1 Kayako 1 Liveresponse 2025-04-03 5.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.
CVE-2000-0591 1 Novell 1 Bordermanager 2025-04-03 5.0 MEDIUM N/A
Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.
CVE-2006-2845 1 Redaxo 1 Redaxo 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php.
CVE-2005-1453 1 Leafnode 1 Leafnode 2025-04-03 5.0 MEDIUM N/A
fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.
CVE-2005-3387 1 Luca Deri 1 Ntop 2025-04-03 4.6 MEDIUM N/A
The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.
CVE-2005-3788 1 Cisco 1 Adaptive Security Appliance Software 2025-04-03 5.4 MEDIUM N/A
Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service."
CVE-2000-0253 1 Craig Dansie 1 Dansie Shopping Cart 2025-04-03 10.0 HIGH N/A
The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.
CVE-2004-0801 4 Conectiva, Linuxprinting.org, Sun and 1 more 4 Linux, Foomatic-filters, Java Desktop System and 1 more 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
CVE-2004-1908 1 Mcafee 1 Freescan 2025-04-03 5.0 MEDIUM N/A
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.
CVE-2006-0981 1 E-merge 1 E-merge Winace 2025-04-03 4.0 MEDIUM N/A
Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.
CVE-2005-2845 1 Ariba 1 Ariba Spend Management Solutions 2025-04-03 5.0 MEDIUM N/A
Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.