Total
29869 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2005-2247 | 1 Moodle | 1 Moodle | 2025-04-03 | 10.0 HIGH | N/A |
|
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
|
|||||
| CVE-2004-1972 | 1 Francisco Burzi | 1 Php-nuke | 2025-04-03 | 7.5 HIGH | N/A |
|
SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.
|
|||||
| CVE-2002-1316 | 1 Iplanet | 1 Iplanet Web Server | 2025-04-03 | 6.8 MEDIUM | N/A |
|
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
|
|||||
| CVE-2006-2846 | 1 Visiongate | 1 Visiongate Portal System | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate Portal System allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
|||||
| CVE-1999-1092 | 1 Iain Lea | 1 Tin | 2025-04-03 | 4.6 MEDIUM | N/A |
|
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
|
|||||
| CVE-2001-0652 | 1 Sun | 1 Sunos | 2025-04-03 | 7.2 HIGH | N/A |
|
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
|
|||||
| CVE-2003-0666 | 1 Microsoft | 1 Wordperfect Converter | 2025-04-03 | 7.5 HIGH | N/A |
|
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.
|
|||||
| CVE-2006-2452 | 1 Gnome | 1 Gdm | 2025-04-03 | 3.7 LOW | N/A |
|
GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.
|
|||||
| CVE-2006-4178 | 1 Freebsd | 1 Freebsd | 2025-04-03 | 4.9 MEDIUM | N/A |
|
Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function to be called with a large length parameter, a different vulnerability than CVE-2006-4172.
|
|||||
| CVE-2006-2102 | 1 Poweriso | 1 Poweriso | 2025-04-03 | 7.8 HIGH | N/A |
|
Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
|
|||||
| CVE-2005-0897 | 1 Magicscripts | 1 E-store Kit-2 | 2025-04-03 | 7.5 HIGH | N/A |
|
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.
|
|||||
| CVE-2004-1213 | 1 Advanced Guestbook | 1 Advanced Guestbook | 2025-04-03 | 6.8 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
|
|||||
| CVE-2005-4282 | 1 Zaygo | 1 Domaincart | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi.
|
|||||
| CVE-2005-2200 | 1 Xerox | 3 Workcentre 2128, Workcentre 2636, Workcentre 3545 | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.
|
|||||
| CVE-1999-1057 | 1 Digital | 1 Vms | 2025-04-03 | 4.6 MEDIUM | N/A |
|
VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.
|
|||||
| CVE-2005-3539 | 1 Hylafax | 1 Hylafax | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
|
|||||
| CVE-2002-0494 | 1 Websight Directory System | 1 Websight Directory System | 2025-04-03 | 7.5 HIGH | N/A |
|
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name.
|
|||||
| CVE-2005-4174 | 1 Efiction Project | 1 Efiction | 2025-04-03 | 7.5 HIGH | N/A |
|
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.
|
|||||
| CVE-2006-4048 | 1 Netious Cms | 1 Netious Cms | 2025-04-03 | 7.5 HIGH | N/A |
|
Netious CMS 0.4 initializes session IDs based on the client IP address, which allows remote attackers to gain access to the administration section when originating from the same IP address as the administrator. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
|||||
| CVE-2002-0552 | 1 Melange | 1 Melange Chat System | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.
|
|||||
| CVE-2004-2580 | 1 Novell | 1 Ichain | 2025-04-03 | 5.8 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.
|
|||||
| CVE-2006-1496 | 1 Vihor | 1 Vihordesign | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.
|
|||||
| CVE-2005-2068 | 1 Freebsd | 1 Freebsd | 2025-04-03 | 5.0 MEDIUM | N/A |
|
FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.
|
|||||
| CVE-2005-2206 | 1 Elemental Software | 1 Cartwiz | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
|
|||||
| CVE-1999-0770 | 1 Checkpoint | 1 Firewall-1 | 2025-04-03 | 2.1 LOW | N/A |
|
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
|
|||||
| CVE-2006-1759 | 1 Swsoft | 1 Confixx | 2025-04-03 | 2.6 LOW | N/A |
|
Cross-site scripting (XSS) vulnerability in allgemein_transfer.php in SWSoft Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the jahr parameter.
|
|||||
| CVE-2006-4057 | 1 Mitch Murray | 1 Eremove | 2025-04-03 | 7.5 HIGH | N/A |
|
Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment.
|
|||||
| CVE-2001-1277 | 1 Wolfram Schneider | 1 Makewhatis | 2025-04-03 | 2.1 LOW | N/A |
|
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
|
|||||
| CVE-2003-0898 | 1 Ibm | 1 Db2 Universal Database | 2025-04-03 | 4.6 MEDIUM | N/A |
|
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
|
|||||
| CVE-2005-4762 | 1 Bea | 1 Weblogic Server | 2025-04-03 | 7.2 HIGH | N/A |
|
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier sometimes stores the boot password in the registry in cleartext, which might allow local users to gain administrative privileges.
|
|||||
| CVE-2005-3778 | 1 Mybulletinboard | 1 Mybulletinboard | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Unspecified vulnerability in MyBulletinBoard (MyBB) before 1.0 PR2 Rev 686 allows attackers to cause a denial of service via unknown vectors.
|
|||||
| CVE-2004-0759 | 1 Mozilla | 1 Mozilla | 2025-04-03 | 6.4 MEDIUM | N/A |
|
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.
|
|||||
| CVE-2005-1388 | 1 Survivor | 1 Survivor | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
|||||
| CVE-1999-0337 | 1 Ibm | 1 Aix | 2025-04-03 | 7.5 HIGH | N/A |
|
AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.
|
|||||
| CVE-2000-0505 | 2 Apache, Ibm | 2 Http Server, Http Server | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
|
|||||
| CVE-2003-0269 | 1 Youbin | 1 Youbin | 2025-04-03 | 7.2 HIGH | N/A |
|
Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.
|
|||||
| CVE-2006-4743 | 1 Wordpress | 1 Wordpress | 2025-04-03 | 5.0 MEDIUM | N/A |
|
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.ph ...
Show More |
|||||
| CVE-2006-1906 | 1 Jjgan852 | 1 Phplister | 2025-04-03 | 2.6 LOW | N/A |
|
Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
|||||
| CVE-2002-0901 | 1 Amanda | 1 Amanda | 2025-04-03 | 10.0 HIGH | N/A |
|
Multiple buffer overflows in Advanced Maryland Automatic Network Disk Archiver (AMANDA) 2.3.0.4 allow (1) remote attackers to execute arbitrary code via long commands to the amindexd daemon, or certain local users to execute arbitrary code via long command line arguments to the programs (2) amcheck, (3) amgetidx, (4) amtrmidx, (5) createindex-dump, or (6) createindex-gnutar.
|
|||||
| CVE-2005-0676 | 1 Phpoutsourcing | 1 Zorum | 2025-04-03 | 7.5 HIGH | N/A |
|
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
|
|||||