Total
29869 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2005-2261 | 1 Mozilla | 3 Firefox, Mozilla, Thunderbird | 2025-04-03 | 7.5 HIGH | N/A |
|
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.
|
|||||
| CVE-2005-0388 | 1 Remstats | 1 Remstats | 2025-04-03 | 7.5 HIGH | N/A |
|
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
|
|||||
| CVE-2005-0917 | 1 Powerdev | 1 Encapsbb | 2025-04-03 | 7.5 HIGH | N/A |
|
PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.
|
|||||
| CVE-2000-0157 | 1 Netbsd | 1 Netbsd | 2025-04-03 | 7.2 HIGH | N/A |
|
NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.
|
|||||
| CVE-2006-0316 | 1 Aol | 1 Aol Client Software | 2025-04-03 | 10.0 HIGH | N/A |
|
Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.
|
|||||
| CVE-2003-0803 | 1 Nokia | 1 Electronic Documentation | 2025-04-03 | 7.5 HIGH | N/A |
|
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.
|
|||||
| CVE-2006-1235 | 1 David Ravenscroft | 1 Hithost | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.
|
|||||
| CVE-2001-0036 | 1 Kth | 1 Kth Kerberos | 2025-04-03 | 1.2 LOW | N/A |
|
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.
|
|||||
| CVE-2006-1166 | 1 Monotone | 1 Monotone | 2025-04-03 | 3.7 LOW | N/A |
|
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.
|
|||||
| CVE-2002-2053 | 1 Cisco | 1 Ios | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.
|
|||||
| CVE-2005-2501 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2025-04-03 | 7.6 HIGH | N/A |
|
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
|
|||||
| CVE-2006-3166 | 1 Free Realty | 1 Free Realty | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.
|
|||||
| CVE-1999-1334 | 1 Elm Development Group | 1 Elm | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.
|
|||||
| CVE-2000-0526 | 1 3r Soft | 1 Mailstudio 2000 | 2025-04-03 | 5.0 MEDIUM | N/A |
|
mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
|
|||||
| CVE-2003-0474 | 1 Ashley Brown | 1 Iweb Server | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
|
|||||
| CVE-1999-0626 | 1 Sun | 1 Rpc.ruserd | 2025-04-03 | N/A | N/A |
|
A version of rusers is running that exposes valid user information to any entity on the network.
|
|||||
| CVE-2004-2503 | 1 Inweb | 1 Mail Server | 2025-04-03 | 5.0 MEDIUM | N/A |
|
INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.
|
|||||
| CVE-2004-1422 | 1 Whm | 1 Whm Autopilot | 2025-04-03 | 5.0 MEDIUM | N/A |
|
WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.
|
|||||
| CVE-2005-1311 | 1 Yappa-ng | 1 Yappa-ng | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
|||||
| CVE-2000-1185 | 1 Itserv Incorporated | 1 Ridewaypn | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.
|
|||||
| CVE-2004-0810 | 1 Netopia | 1 Timbuktu Pro Mac | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.
|
|||||
| CVE-2004-0490 | 1 Cpanel | 1 Cpanel | 2025-04-03 | 7.2 HIGH | N/A |
|
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.
|
|||||
| CVE-2004-1721 | 1 Merak | 1 Mail Server | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
|
|||||
| CVE-2003-1319 | 1 Smartftp | 1 Smartftp | 2025-04-03 | 7.6 HIGH | N/A |
|
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
|
|||||
| CVE-2004-1222 | 1 Darryl Burgdorf | 1 Weblibs | 2025-04-03 | 10.0 HIGH | N/A |
|
weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.
|
|||||
| CVE-2006-2282 | 1 X7 Group | 1 X7 Chat | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to the avatar parameter in register.php.
|
|||||
| CVE-2005-3247 | 1 Ethereal Group | 1 Ethereal | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
|
|||||
| CVE-2005-1040 | 1 Novell | 1 Linux Desktop | 2025-04-03 | 7.2 HIGH | N/A |
|
Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."
|
|||||
| CVE-2005-3667 | 1 Internet Key Exchange | 1 Internet Key Exchange | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable. In addition, since "denial of service" is an impact and not a ...
Show More |
|||||
| CVE-2003-1301 | 1 Sun | 1 Jre | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.
|
|||||
| CVE-2001-1338 | 1 Beck Ipc Gmbh | 1 Ipc At Chip Telnetd Server | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.
|
|||||
| CVE-2006-1973 | 1 Linksys | 1 Rt31p2 | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.
|
|||||
| CVE-2005-0159 | 1 Debian | 2 Debian Linux, Toolchain-source | 2025-04-03 | 4.6 MEDIUM | N/A |
|
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
|
|||||
| CVE-2004-1680 | 1 Pingtel | 1 Xpressa | 2025-04-03 | 5.0 MEDIUM | N/A |
|
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.
|
|||||
| CVE-2000-1070 | 1 Cgi-world | 2 Poll It, Poll It Pro | 2025-04-03 | 5.0 MEDIUM | N/A |
|
pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.
|
|||||
| CVE-2006-0757 | 1 Hivemail | 1 Hivemail | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderid parameter in folders.update.php, and possibly certain parameters in (4) calendar.event.php, (5) index.php, (6) pop.download.php, (7) read.bounce.php, (8) rules.block.php, (9) language.php, and (10) certain other scripts, as demonstrated by an add ...
Show More |
|||||
| CVE-2001-0208 | 1 Microfocus | 1 Cobol | 2025-04-03 | 4.6 MEDIUM | N/A |
|
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
|
|||||
| CVE-2003-1122 | 1 Scriptlogic | 1 Scriptlogic | 2025-04-03 | 2.1 LOW | N/A |
|
ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.
|
|||||
| CVE-2006-4836 | 1 Codeworx Technologies | 1 Dcp-portal | 2025-04-03 | 5.1 MEDIUM | N/A |
|
SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.php vector is already covered by CVE-2005-4227.
|
|||||
| CVE-2006-2829 | 1 Tibco | 3 Hawk, Hawk Monitoring Agent, Runtime Agent | 2025-04-03 | 6.8 MEDIUM | N/A |
|
Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma.
|
|||||