Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-1102 1 Hummingbird 1 Cyberdocs 2025-04-03 5.0 MEDIUM N/A
Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.
CVE-2001-0333 1 Microsoft 1 Internet Information Server 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
CVE-2000-0901 1 Juergen 1 Weigert Screen 2025-04-03 4.6 MEDIUM N/A
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.
CVE-2003-0060 1 Mit 1 Kerberos 5 2025-04-03 7.5 HIGH N/A
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.
CVE-2005-1205 1 Microsoft 1 Windows 2003 Server 2025-04-03 5.0 MEDIUM N/A
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
CVE-2003-0878 1 Apple 1 Mac Os X 2025-04-03 2.1 LOW N/A
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.
CVE-2002-1789 1 Newsx 1 Newsx 2025-04-03 7.2 HIGH N/A
Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function.
CVE-2005-2166 1 Frozenplague.net 1 Plague News System 2025-04-03 5.0 MEDIUM N/A
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2005-4302 1 Indexcor 1 Ezdatabase 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.
CVE-2006-3670 1 Rabox 1 Winlpd 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515.
CVE-2004-0527 1 Kde 1 Konqueror 2025-04-03 5.0 MEDIUM N/A
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
CVE-2005-1779 1 Maxwebportal 1 Maxwebportal 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.
CVE-2006-4913 1 Alstrasoft 1 E-friends 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file.
CVE-1999-1220 1 Great Circle Associates 1 Majordomo 2025-04-03 7.5 HIGH N/A
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
CVE-2005-1188 1 Comersus Open Technologies 1 Comersus Cart 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.
CVE-2001-1077 1 Rxvt 1 Rxvt 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.
CVE-2004-0014 1 Nd 1 Nd 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.
CVE-2000-0771 1 Microsoft 1 Windows 2000 2025-04-03 2.1 LOW N/A
Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
CVE-2003-1052 1 Ibm 2 Db2, Db2 Universal Database 2025-04-03 7.2 HIGH N/A
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
CVE-2005-2986 1 Ahnlab 3 V3 Virusblock 2005, V3net, V3pro 2004 2025-04-03 7.5 HIGH N/A
The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges.