Vulnerabilities (CVE)

Total 345982 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0228 1 Grsecurity 1 Grsecurity Kernel Patch 2026-04-16 7.2 HIGH N/A
The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.
CVE-2003-1283 1 Kazaa 1 Kazaa Media Desktop 2026-04-16 7.5 HIGH N/A
KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.
CVE-2006-0050 1 Debian 1 Debian Linux 2026-04-16 1.2 LOW N/A
snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.
CVE-2002-2282 1 Mcafee 1 Virusscan 2026-04-16 6.9 MEDIUM N/A
McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.
CVE-1999-1449 1 Sun 1 Sunos 2026-04-16 2.1 LOW N/A
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.
CVE-2003-0852 2 Sylpheed, Sylpheed-claws 2 Sylpheed, Sylpheed-claws 2026-04-16 5.0 MEDIUM N/A
Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.
CVE-2000-1101 1 Texas Imperial Software 1 Wftpd 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
CVE-1999-0138 7 Apple, Digital, Freebsd and 4 more 9 A Ux, Osf 1, Freebsd and 6 more 2026-04-16 7.2 HIGH N/A
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
CVE-2004-2026 1 Apsis 1 Pound 2026-04-16 7.5 HIGH N/A
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.
CVE-1999-1427 1 Sun 1 Solstice Adminsuite 2026-04-16 6.2 MEDIUM N/A
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.
CVE-2001-1041 1 Oracle 1 Database Server 2026-04-16 2.1 LOW N/A
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
CVE-2006-4321 1 Coppermine 1 Coppermine Photo Gallery 2026-04-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
CVE-2005-1355 1 Includer.cgi 1 Includer.cgi 2026-04-16 5.0 MEDIUM N/A
includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.
CVE-2005-2870 1 Sun 1 Solaris 2026-04-16 7.5 HIGH N/A
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
CVE-2006-4740 1 Jetbox 1 Jetbox Cms 2026-04-16 5.0 MEDIUM N/A
Jetbox CMS allows remote attackers to obtain sensitive information via a direct request for certain files, which reveal the path in an error message.
CVE-2001-0649 1 Apple 1 Personal Web Sharing 2026-04-16 5.0 MEDIUM N/A
Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.
CVE-2002-0871 1 Xinetd 1 Xinetd 2026-04-16 2.1 LOW N/A
xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.
CVE-2004-2757 1 Novell 1 Ichain 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.
CVE-2003-0616 1 Mcafee 1 Epolicy Orchestrator 2026-04-16 7.5 HIGH N/A
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
CVE-2003-0712 1 Microsoft 1 Exchange Server 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.