Vulnerabilities (CVE)

Total 346082 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0319 1 Eric Allman 1 Sendmail 2026-04-16 5.0 MEDIUM N/A
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
CVE-2005-1715 1 Ej3 1 Topo 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.
CVE-2004-1313 1 Webroot Software 1 My Firewall Plus 2026-04-16 7.2 HIGH N/A
The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.
CVE-2006-3515 1 Myiosoft.com 1 Ajaxportal 2026-04-16 7.5 HIGH N/A
SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
CVE-2001-0172 2 Hans Reiser, Suse 2 Reiserfs, Suse Linux 2026-04-16 7.2 HIGH N/A
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
CVE-2005-3711 1 Apple 1 Quicktime 2026-04-16 7.5 HIGH N/A
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
CVE-2006-1146 1 Cor Entertainment 1 Alien Arena 2006 2026-04-16 6.5 MEDIUM N/A
Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server.
CVE-2006-0460 1 Bomberclone 1 Bomberclone 2026-04-16 7.5 HIGH N/A
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.
CVE-2005-1404 1 Myphp Forum 1 Myphp Forum 2026-04-16 5.0 MEDIUM N/A
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
CVE-2001-1483 1 Nrl.navy 1 One-time Passwords In Everything 2026-04-16 5.0 MEDIUM N/A
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.
CVE-1999-0034 4 Bsdi, Larry Wall, Redhat and 1 more 4 Bsd Os, Perl, Linux and 1 more 2026-04-16 7.2 HIGH N/A
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
CVE-2001-0082 1 Checkpoint 1 Firewall-1 2026-04-16 7.5 HIGH N/A
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.
CVE-2006-2680 1 Php4script 1 Az Photo Album Script Pro 2026-04-16 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.
CVE-2006-4481 1 Php 1 Php 2026-04-16 7.2 HIGH N/A
The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.
CVE-2003-0968 1 Freeradius 1 Freeradius 2026-04-16 10.0 HIGH N/A
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.
CVE-2006-4948 1 Prosysinfo 1 Tftp Server Tftpdwin 2026-04-16 7.5 HIGH N/A
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2004-1166 1 Microsoft 2 Ie, Internet Explorer 2026-04-16 7.5 HIGH N/A
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
CVE-2005-3432 1 Thomas Rybak 1 Minigal 2 2026-04-16 5.0 MEDIUM N/A
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
CVE-2000-0436 1 Metaproducts 1 Offline Explorer 2026-04-16 5.0 MEDIUM N/A
MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.
CVE-2006-1470 1 Apple 2 Mac Os X, Mac Os X Server 2026-04-16 5.0 MEDIUM N/A
OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.