Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29557 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2393 1 Sun 1 Jsse 2025-04-03 7.5 HIGH N/A
Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.
CVE-2001-0972 1 Surf-net 1 Asp Forum 2025-04-03 10.0 HIGH N/A
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
CVE-2005-0430 1 Id Software 1 Quake 3 Engine 2025-04-03 5.0 MEDIUM N/A
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.
CVE-2006-2486 1 Yapbb 1 Yapbb 2025-04-03 6.4 MEDIUM N/A
SQL injection vulnerability in find.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the userID parameter.
CVE-2002-0398 1 Red-m 1 1050ap Lan Acess Point 2025-04-03 10.0 HIGH N/A
Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name.
CVE-2006-2242 1 Acftp 1 Acftp 2025-04-03 5.0 MEDIUM N/A
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command.
CVE-2002-1268 1 Apple 1 Mac Os X 2025-04-03 4.6 MEDIUM N/A
Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."
CVE-2002-2189 2 Activxperts Software, Microsoft 2 Activwebserver, Windows 2003 Server 2025-04-03 5.1 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
CVE-2001-1488 1 Open Projects Network 1 Open Projects Network Ircd 2025-04-03 5.0 MEDIUM N/A
Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.
CVE-1999-0069 1 Sun 1 Sunos 2025-04-03 7.2 HIGH 8.4 HIGH
Solaris ufsrestore buffer overflow.
CVE-2002-0489 1 Linux Directory Penguin 1 Nslookup 2025-04-03 10.0 HIGH N/A
Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters.
CVE-2002-0263 1 Ezne.net 1 Ezboard 2000 2025-04-03 7.5 HIGH N/A
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.
CVE-2005-4160 1 Torrential 1 Torrential 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.
CVE-2006-2886 1 Jam Warehouse 1 Knowledgetree Open Source 2025-04-03 4.3 MEDIUM N/A
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.
CVE-2004-1858 1 Hp 1 Web Jetadmin 2025-04-03 5.0 MEDIUM N/A
HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character.
CVE-2005-3992 1 Wineggdropshell 1 Wineggdropshell 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server.
CVE-2001-0070 1 Upland Solutions 1 1st Up Mail Server 2025-04-03 10.0 HIGH N/A
Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.
CVE-2000-0555 1 Lilikoi 1 Ceilidh 2025-04-03 5.0 MEDIUM N/A
Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.
CVE-2006-1697 1 Matt Wright 1 Matt Wright Guestbook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message.
CVE-2006-1856 1 Linux 1 Linux Kernel 2025-04-03 7.5 HIGH N/A
Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.