Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0767 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
CVE-2003-0040 2 Double Precision Incorporated, Inter7 2 Courier Mta, Courier-imap 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.
CVE-2003-0270 1 Apple 1 802.11n 2025-04-03 7.6 HIGH N/A
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.
CVE-2005-2333 1 Seo-board 1 Seo-board 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.
CVE-2002-1453 1 Mywebserver 1 Mywebserver 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.
CVE-2004-0652 1 Bea 1 Weblogic Server 2025-04-03 7.2 HIGH N/A
BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
CVE-2002-1870 1 Sws 1 Sws Simple Web Server 2025-04-03 7.5 HIGH N/A
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.
CVE-2006-2136 1 Aznews 1 Aznews 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-1999-1552 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.
CVE-2001-1445 1 Lotus 1 Domino Mail Server 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.
CVE-2005-0995 1 Early Impact 1 Productcart 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.
CVE-2002-0937 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
CVE-2002-0774 1 Hosting Controller 1 Hosting Controller 2025-04-03 10.0 HIGH N/A
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.
CVE-2003-0603 1 Mozilla 1 Bugzilla 2025-04-03 2.1 LOW N/A
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.
CVE-2002-2370 1 Sws 1 Sws Simple Web Server 2025-04-03 5.0 MEDIUM N/A
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
CVE-2005-1554 1 Wowbb 1 Wowbb Web Forum 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.
CVE-2001-0447 1 Software602 1 602pro Lan Suite 2025-04-03 7.5 HIGH N/A
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.
CVE-2006-3718 1 Oracle 1 Exchange 2025-04-03 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Oracle Exchange for Oracle E-Business Suite and Applications 6.2.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS16 and (2) APPS17.
CVE-1999-1079 1 Ibm 1 Aix 2025-04-03 4.6 MEDIUM N/A
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
CVE-2002-0114 1 Emc 1 Networker 2025-04-03 4.6 MEDIUM N/A
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.