Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Angry Yack Logo
Total 29869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2261 1 Mozilla 3 Firefox, Mozilla, Thunderbird 2025-04-03 7.5 HIGH N/A
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.
CVE-2005-0388 1 Remstats 1 Remstats 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
CVE-2005-0917 1 Powerdev 1 Encapsbb 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.
CVE-2000-0157 1 Netbsd 1 Netbsd 2025-04-03 7.2 HIGH N/A
NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.
CVE-2006-0316 1 Aol 1 Aol Client Software 2025-04-03 10.0 HIGH N/A
Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2003-0803 1 Nokia 1 Electronic Documentation 2025-04-03 7.5 HIGH N/A
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.
CVE-2006-1235 1 David Ravenscroft 1 Hithost 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.
CVE-2001-0036 1 Kth 1 Kth Kerberos 2025-04-03 1.2 LOW N/A
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.
CVE-2006-1166 1 Monotone 1 Monotone 2025-04-03 3.7 LOW N/A
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.
CVE-2002-2053 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.
CVE-2005-2501 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.6 HIGH N/A
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
CVE-2006-3166 1 Free Realty 1 Free Realty 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.
CVE-1999-1334 1 Elm Development Group 1 Elm 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.
CVE-2000-0526 1 3r Soft 1 Mailstudio 2000 2025-04-03 5.0 MEDIUM N/A
mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2003-0474 1 Ashley Brown 1 Iweb Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
CVE-1999-0626 1 Sun 1 Rpc.ruserd 2025-04-03 N/A N/A
A version of rusers is running that exposes valid user information to any entity on the network.
CVE-2004-2503 1 Inweb 1 Mail Server 2025-04-03 5.0 MEDIUM N/A
INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.
CVE-2004-1422 1 Whm 1 Whm Autopilot 2025-04-03 5.0 MEDIUM N/A
WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.
CVE-2005-1311 1 Yappa-ng 1 Yappa-ng 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2000-1185 1 Itserv Incorporated 1 Ridewaypn 2025-04-03 5.0 MEDIUM N/A
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.
CVE-2004-0810 1 Netopia 1 Timbuktu Pro Mac 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.
CVE-2004-0490 1 Cpanel 1 Cpanel 2025-04-03 7.2 HIGH N/A
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
CVE-2004-1721 1 Merak 1 Mail Server 2025-04-03 5.0 MEDIUM N/A
The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
CVE-2003-1319 1 Smartftp 1 Smartftp 2025-04-03 7.6 HIGH N/A
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
CVE-2004-1222 1 Darryl Burgdorf 1 Weblibs 2025-04-03 10.0 HIGH N/A
weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.
CVE-2006-2282 1 X7 Group 1 X7 Chat 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to the avatar parameter in register.php.
CVE-2005-3247 1 Ethereal Group 1 Ethereal 2025-04-03 5.0 MEDIUM N/A
The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
CVE-2005-1040 1 Novell 1 Linux Desktop 2025-04-03 7.2 HIGH N/A
Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."
CVE-2005-3667 1 Internet Key Exchange 1 Internet Key Exchange 2025-04-03 5.0 MEDIUM N/A
Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable. In addition, since "denial of service" is an impact and not a ...

Show More

CVE-2003-1301 1 Sun 1 Jre 2025-04-03 5.0 MEDIUM N/A
Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.
CVE-2001-1338 1 Beck Ipc Gmbh 1 Ipc At Chip Telnetd Server 2025-04-03 5.0 MEDIUM N/A
Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.
CVE-2006-1973 1 Linksys 1 Rt31p2 2025-04-03 5.0 MEDIUM N/A
Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.
CVE-2005-0159 1 Debian 2 Debian Linux, Toolchain-source 2025-04-03 4.6 MEDIUM N/A
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2004-1680 1 Pingtel 1 Xpressa 2025-04-03 5.0 MEDIUM N/A
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.
CVE-2000-1070 1 Cgi-world 2 Poll It, Poll It Pro 2025-04-03 5.0 MEDIUM N/A
pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.
CVE-2006-0757 1 Hivemail 1 Hivemail 2025-04-03 7.5 HIGH N/A
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an add ...

Show More

CVE-2001-0208 1 Microfocus 1 Cobol 2025-04-03 4.6 MEDIUM N/A
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
CVE-2003-1122 1 Scriptlogic 1 Scriptlogic 2025-04-03 2.1 LOW N/A
ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.
CVE-2006-4836 1 Codeworx Technologies 1 Dcp-portal 2025-04-03 5.1 MEDIUM N/A
SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.php vector is already covered by CVE-2005-4227.
CVE-2006-2829 1 Tibco 3 Hawk, Hawk Monitoring Agent, Runtime Agent 2025-04-03 6.8 MEDIUM N/A
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.