Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Angry Yack Logo
Total 29869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2681 1 Peersec Networks 1 Matrixssl 2025-04-03 7.5 HIGH N/A
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.
CVE-2006-3119 1 Fbi 1 Fbi 2025-04-03 5.1 MEDIUM N/A
The fbgs framebuffer Postscript/PDF viewer in fbi before 2.01 has a typo that prevents a filter from working correctly, which allows user-assisted attackers to bypass the filter and execute malicious Postscript commands.
CVE-2006-3126 1 Julian Pawlowski 1 Capi4hylafax 2025-04-03 7.5 HIGH N/A
c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null (\0) and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.
CVE-2004-0720 1 Apple 1 Safari 2025-04-03 7.5 HIGH N/A
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
CVE-2005-0430 1 Id Software 1 Quake 3 Engine 2025-04-03 5.0 MEDIUM N/A
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.
CVE-2005-4193 1 Usebb 1 Usebb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable.
CVE-2005-3757 1 Google 2 Mini Search Appliance, Search Appliance 2025-04-03 7.5 HIGH N/A
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.
CVE-2006-0992 1 Novell 1 Groupwise Messenger 2025-04-03 10.0 HIGH N/A
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.
CVE-1999-1451 1 Microsoft 2 Internet Information Server, Site Server 2025-04-03 5.0 MEDIUM N/A
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
CVE-1999-0401 1 Linux 1 Linux Kernel 2025-04-03 3.7 LOW N/A
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
CVE-2001-1124 1 Hp 1 Hp-ux 2025-04-03 5.0 MEDIUM N/A
rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.
CVE-2005-4733 1 Netbsd 1 Netbsd 2025-04-03 4.9 MEDIUM N/A
NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users to cause a denial of service (infinite loop and system hang) by calling the F_CLOSEM fcntl with a parameter value of 0.
CVE-2000-0133 1 H. Nomura 1 Tiny Ftpdaemon 2025-04-03 10.0 HIGH N/A
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.
CVE-2004-0334 1 Innomedia 1 Innomedia Videophone 2025-04-03 5.0 MEDIUM N/A
InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.
CVE-2005-2995 1 Bacula 1 Bacula 2025-04-03 3.6 LOW N/A
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.
CVE-2003-0282 2 Info-zip, Sco 3 Unzip, Openlinux Server, Openlinux Workstation 2025-04-03 2.6 LOW N/A
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
CVE-2005-0798 1 Novell 1 Ichain 2025-04-03 7.5 HIGH N/A
Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.
CVE-2006-0558 1 Linux 1 Linux Kernel 2025-04-03 4.9 MEDIUM N/A
perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.
CVE-2006-0674 1 Ibm 1 Aix 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.
CVE-2006-3514 1 Phpblogger 1 Php-blogger 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters.
CVE-2002-1959 1 Nagios 1 Nagios 2025-04-03 10.0 HIGH N/A
Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.
CVE-2003-0074 1 Plptools 1 Plptools 2025-04-03 7.2 HIGH N/A
Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.
CVE-2002-0483 1 Francisco Burzi 1 Php-nuke 2025-04-03 5.0 MEDIUM N/A
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
CVE-2005-1899 1 Rakkarsoft 1 Raknet 2025-04-03 5.0 MEDIUM N/A
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.
CVE-2002-1391 1 Gert Doering 1 Mgetty 2025-04-03 7.5 HIGH N/A
Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long CallerName argument.
CVE-2004-1910 1 Symantec 1 Security Check Virus Detection 2025-04-03 5.0 MEDIUM N/A
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.
CVE-2005-1911 1 Leafnode 1 Leafnode 2025-04-03 5.0 MEDIUM N/A
The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).
CVE-2004-2094 1 Darkwet 1 Webcam Xp 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.
CVE-1999-0150 1 Gnu 1 Fingerd 2025-04-03 7.5 HIGH N/A
The Perl fingerd program allows arbitrary command execution from remote users.
CVE-2005-0852 1 Microsoft 1 Windows Xp 2025-04-03 2.1 LOW N/A
Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
CVE-2006-4108 1 Drupal 1 Bibliography Module 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2002-1146 1 Gnu 1 Glibc 2025-04-03 5.0 MEDIUM N/A
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
CVE-1999-0375 1 Network Flight Recorder 1 Network Flight Recorder 2025-04-03 7.5 HIGH N/A
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
CVE-2003-0509 1 Cyberstrong 1 Eshop 2025-04-03 10.0 HIGH N/A
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.
CVE-2006-0909 1 Invision Power Services 1 Invision Power Board 2025-04-03 5.0 MEDIUM N/A
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subs ...

Show More

CVE-2002-2144 1 Free Peers 1 Bearshare 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot) characters.
CVE-2006-1541 1 Ezaspsite 1 Ezaspsite 2025-04-03 7.8 HIGH N/A
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.
CVE-2004-1826 1 Mambo 1 Mambo Open Source 4.5 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2004-0069 1 Hd Soft 1 Windows Ftp Server 2025-04-03 7.5 HIGH N/A
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
CVE-2005-1576 1 Mozilla 1 Firefox 2025-04-03 2.6 LOW N/A
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.