Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Angry Yack Logo
Total 29869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0664 1 Powerportal 1 Powerportal 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter.
CVE-2000-0537 1 Tolis Group 1 Bru 2025-04-03 7.2 HIGH N/A
BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.
CVE-1999-0188 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The passwd command in Solaris can be subjected to a denial of service.
CVE-2002-1449 1 Frederic Tyndiuk 1 Eupload 2025-04-03 7.5 HIGH N/A
eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
CVE-2005-2763 1 Openttd 1 Openttd 2025-04-03 7.5 HIGH N/A
Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
CVE-2000-1181 1 Realnetworks 1 Realserver 2025-04-03 5.0 MEDIUM N/A
Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.
CVE-2005-4280 1 Kitware 1 Cmake 2025-04-03 7.2 HIGH N/A
Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
CVE-2001-1337 1 Beck Ipc Gmbh 1 Ipc At Chip Embedded-webserver 2025-04-03 5.0 MEDIUM N/A
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.
CVE-2006-3234 1 Looknet 1 Fineshop 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.
CVE-2006-1206 1 Dropbear Ssh Project 1 Dropbear Ssh 2025-04-03 5.0 MEDIUM N/A
Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.
CVE-2005-4126 1 Realnetworks 1 Realplayer 2025-04-03 7.5 HIGH N/A
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not provide any verifiable information. It has been posted by a reliable reporter with a prerelease disclosure policy. This item has only been assigned a CVE identifier for tracki ...

Show More

CVE-2005-3509 1 Jportal 1 Jportal Web Portal 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.
CVE-2002-0856 1 Oracle 2 Database Server, Oracle9i 2025-04-03 5.0 MEDIUM N/A
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
CVE-2005-2640 3 Juniper, Neoteris, Netscreen 16 Netscreen-5gt, Netscreen-idp, Netscreen-idp 10 and 13 more 2025-04-03 5.0 MEDIUM N/A
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
CVE-2003-1077 1 Sun 1 Solaris 2025-04-03 2.1 LOW N/A
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).
CVE-1999-0024 6 Bsdi, Ibm, Isc and 3 more 12 Bsd Os, Aix, Bind and 9 more 2025-04-03 5.0 MEDIUM N/A
DNS cache poisoning via BIND, by predictable query IDs.
CVE-2006-3759 1 Mybulletinboard 1 Mybulletinboard 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."
CVE-2005-2167 1 Frozenplague.net 1 Plague News System 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
CVE-1999-0811 1 Samba 1 Samba 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Samba smbd program via a malformed message command.
CVE-2004-1834 1 Apache 1 Http Server 2025-04-03 2.1 LOW N/A
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
CVE-2005-0006 1 Ethereal Group 1 Ethereal 2025-04-03 5.0 MEDIUM N/A
The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).
CVE-2005-1803 1 Net Portal Dynamic System 1 Net Portal Dynamic System 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the categories parameter to faq.php, (5) the lettre parameter to the glossaire module, (6) the title parameter to reviews.php, or (7) the image_subject parameter to reply.php.
CVE-1999-0201 1 Ftp 1 Ftp 2025-04-03 6.4 MEDIUM N/A
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
CVE-2000-0403 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.
CVE-2006-1744 1 Joey Hess 1 Bsdgames 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
CVE-2006-2269 1 Mywebland 1 Mybloggie 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.
CVE-2002-0670 1 Pingtel 1 Xpressa 2025-04-03 7.5 HIGH N/A
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.
CVE-2005-0278 1 3com 1 3cdaemon 2025-04-03 5.0 MEDIUM N/A
The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.
CVE-2005-3215 1 Mcafee 1 Antivirus Engine 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
CVE-2003-1104 1 Ibm 1 Tivoli Firewall Toolbox 2025-04-03 10.0 HIGH N/A
Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.
CVE-2000-0412 1 Napster 1 Knapster 2025-04-03 7.5 HIGH N/A
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.
CVE-2005-0077 4 Debian, Gentoo, Redhat and 1 more 5 Debian Linux, Linux, Enterprise Linux and 2 more 2025-04-03 2.1 LOW N/A
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
CVE-2006-2445 1 Linux 1 Linux Kernel 2025-04-03 4.0 MEDIUM N/A
Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.
CVE-2006-3024 1 Evgenius 1 Evgenius Counter 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2) daily.php.
CVE-2006-2642 1 Php-residence 1 Php-residence 2025-04-03 4.3 MEDIUM N/A
** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) vulnerability in Marco M. F. De Santis Php-residence 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via "any of its input." NOTE: the original disclosure is based on vague researcher claims without vendor acknowledgement; therefore this identifier cannot be linked with any future identifier that identifies more specific vectors. Perhaps this sh ...

Show More

CVE-2005-2705 1 Mozilla 2 Firefox, Mozilla Suite 2025-04-03 7.5 HIGH N/A
Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.
CVE-2001-0463 1 Acme Labs 1 Perlcal 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
CVE-2004-0591 1 Inter7 1 Sqwebmail 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.
CVE-2006-2526 1 Power Place 1 Php Easy Galerie 2025-04-03 6.4 MEDIUM N/A
PHP remote file inclusion vulnerability in index.php in PHP Easy Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.
CVE-2002-0431 1 Dave Lawrence 1 Xtux 2025-04-03 5.0 MEDIUM N/A
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.