Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Angry Yack Logo
Total 29869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0028 1 Sgi 1 Irix 2025-04-03 7.2 HIGH N/A
root privileges via buffer overflow in login/scheme command on SGI IRIX systems.
CVE-2004-2521 1 Geeos Team 1 Gattaca Server 2003 2025-04-03 5.0 MEDIUM N/A
Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).
CVE-2002-1334 1 Bizdesign 1 Imagefolio 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
CVE-2001-0025 1 Leif M. Wright 1 Ad.cgi 2025-04-03 10.0 HIGH N/A
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
CVE-2002-0984 1 Light 1 Light 2025-04-03 7.5 HIGH N/A
The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code.
CVE-2001-1261 1 Avaya 1 Argent Office 2025-04-03 5.0 MEDIUM N/A
Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.
CVE-2001-1259 1 Avaya 1 Argent Office 2025-04-03 5.0 MEDIUM N/A
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.
CVE-2004-1907 1 Kerio 1 Personal Firewall 2025-04-03 2.6 LOW N/A
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".
CVE-2004-1262 1 Stuart Cunningham 1 Bsb2ppm 2025-04-03 10.0 HIGH N/A
Buffer overflow in the bsb_open_header function in libbsb for bsb2ppm 0.0.6 allows remote attackers to execute arbitrary code via crafted BSB pictures.
CVE-2004-0302 1 Fools Workshop 1 Owls Workshop 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.
CVE-2006-3000 1 Okscripts 1 Okarticles 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
CVE-1999-0697 1 Sco 1 Openserver 2025-04-03 7.2 HIGH N/A
SCO Doctor allows local users to gain root privileges through a Tools option.
CVE-2001-1531 1 Apple 1 Claris Emailer 2025-04-03 7.5 HIGH N/A
Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.
CVE-2000-0241 1 Vqsoft 1 Vqserver 2025-04-03 5.0 MEDIUM N/A
vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.
CVE-2001-1230 1 Icecast 1 Icecast 2025-04-03 7.5 HIGH N/A
Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
CVE-2000-0043 1 Camshot 1 Webcam Http Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.
CVE-2002-0795 1 Freebsd 1 Freebsd 2025-04-03 2.1 LOW N/A
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.
CVE-2004-0900 1 Microsoft 1 Windows Nt 2025-04-03 10.0 HIGH N/A
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."
CVE-2005-0498 1 Gigafast Ethernet 1 Gigafast Router 2025-04-03 7.5 HIGH N/A
Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.
CVE-2006-0343 1 Hitachi 2 Jpi Netsight Ii Port Discovery Advance, Jpi Netsight Ii Port Discovery Standard 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
CVE-2006-3927 1 Php Pro Bid 1 Php Pro Bid 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter.
CVE-2006-3653 1 Microsoft 1 Works 2025-04-03 2.6 LOW N/A
wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
CVE-2002-0373 1 Microsoft 1 Windows Media Player 2025-04-03 7.2 HIGH N/A
The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
CVE-2004-1321 1 Asante 1 Fm2008 Managed Ethernet Switch 2025-04-03 7.5 HIGH N/A
The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.
CVE-2006-1598 1 An 1 An-httpd 2025-04-03 7.8 HIGH N/A
AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with (1) dot and (2) space characters in the file extension.
CVE-2006-2660 1 Php 1 Php 2025-04-03 2.1 LOW N/A
Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
CVE-2001-0368 1 Free Peers 1 Bearshare 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack.
CVE-2001-0999 1 Microsoft 1 Outlook Express 2025-04-03 7.5 HIGH N/A
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
CVE-2004-2231 1 Zero G 1 Installanywhere 2025-04-03 1.2 LOW N/A
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
CVE-2005-4399 1 Libertas Solutions 1 Libertas Enterprise Cms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.
CVE-2004-2277 1 Agsm 1 Agsm 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response.
CVE-2005-0340 1 Apple 1 Afp Server 2025-04-03 5.0 MEDIUM N/A
Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.
CVE-2005-1693 3 Broadcom, Ca, Zonelabs 14 Etrust Antivirus, Etrust Antivirus Ee, Etrust Ez Armor and 11 more 2025-04-03 10.0 HIGH N/A
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overfl ...

Show More

CVE-2003-1093 1 Bea 1 Weblogic Server 2025-04-03 4.6 MEDIUM N/A
BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.
CVE-2000-0203 1 Trend Micro 1 Officescan 2025-04-03 5.0 MEDIUM N/A
The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.
CVE-2006-2274 1 Lksctp 1 Stream Control Transmission Protocol 2025-04-03 5.0 MEDIUM N/A
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.
CVE-2006-0547 1 Oracle 1 Database Server 2025-04-03 7.5 HIGH N/A
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this is ...

Show More

CVE-2005-0611 1 Realnetworks 3 Helix Player, Realone Player, Realplayer 2025-04-03 5.1 MEDIUM N/A
Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.
CVE-2005-3375 1 Ikarus 1 Ikarus Antivirus 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in Ikarus demo version allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
CVE-2006-4016 1 Toenda Software Development 1 Toendacms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via the s parameter.