Total
29869 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2006-0704 | 1 Ie | 1 Ie Integrator | 2025-04-03 | 2.6 LOW | N/A |
|
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
|
|||||
| CVE-2004-1184 | 4 Gnu, Redhat, Sgi and 1 more | 4 Enscript, Fedora Core, Propack and 1 more | 2025-04-03 | 4.6 MEDIUM | N/A |
|
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
|
|||||
| CVE-2000-0749 | 1 Freebsd | 1 Freebsd | 2025-04-03 | 7.2 HIGH | N/A |
|
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
|
|||||
| CVE-2000-0027 | 1 Ibm | 1 Network Station Manager | 2025-04-03 | 6.2 MEDIUM | N/A |
|
IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
|
|||||
| CVE-2006-1561 | 1 Vscripts | 1 Vbook | 2025-04-03 | 5.1 MEDIUM | N/A |
|
SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter.
|
|||||
| CVE-2001-0354 | 1 Thenet | 1 Checkbo | 2025-04-03 | 5.0 MEDIUM | N/A |
|
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.
|
|||||
| CVE-2004-1388 | 1 Berlios | 1 Gps Daemon | 2025-04-03 | 7.5 HIGH | N/A |
|
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.
|
|||||
| CVE-2004-0453 | 1 Vice | 1 Vice | 2025-04-03 | 7.2 HIGH | N/A |
|
Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.
|
|||||
| CVE-2006-3141 | 1 Dpivision | 1 Tradingeye Shop | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye Shop R4 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter.
|
|||||
| CVE-2002-1443 | 1 Google | 1 Toolbar | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
|
|||||
| CVE-2002-0328 | 1 Ikonboard.com | 1 Ikonboard | 2025-04-03 | 7.5 HIGH | N/A |
|
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.
|
|||||
| CVE-2006-3804 | 1 Mozilla | 2 Seamonkey, Thunderbird | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
|
|||||
| CVE-2001-0087 | 1 Michael Glickman | 1 Itetris | 2025-04-03 | 7.2 HIGH | N/A |
|
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.
|
|||||
| CVE-2002-0568 | 1 Oracle | 3 Application Server, Oracle8i, Oracle9i | 2025-04-03 | 2.1 LOW | N/A |
|
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
|
|||||
| CVE-2001-1314 | 1 Critical Path | 2 Injoin Directory Server, Livecontent Directory | 2025-04-03 | 7.5 HIGH | N/A |
|
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
|
|||||
| CVE-2004-2173 | 1 Early Impact | 1 Productcart | 2025-04-03 | 7.5 HIGH | N/A |
|
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.
|
|||||
| CVE-2004-1791 | 1 Edimax | 1 Full Rate Adsl Router | 2025-04-03 | 7.5 HIGH | N/A |
|
The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.
|
|||||
| CVE-1999-0959 | 1 Sgi | 1 Irix | 2025-04-03 | 7.2 HIGH | N/A |
|
IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.
|
|||||
| CVE-2001-1488 | 1 Open Projects Network | 1 Open Projects Network Ircd | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon.
|
|||||
| CVE-2003-0036 | 1 Rildo Pragana | 1 Ml85p | 2025-04-03 | 6.2 MEDIUM | N/A |
|
ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".
|
|||||
| CVE-1999-0467 | 1 Webcom | 1 Cgi Guestbook | 2025-04-03 | 5.0 MEDIUM | N/A |
|
The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.
|
|||||
| CVE-2003-0153 | 1 Mozilla | 1 Bonsai | 2025-04-03 | 5.0 MEDIUM | N/A |
|
bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.
|
|||||
| CVE-2005-1781 | 1 Mailenable | 2 Mailenable Enterprise, Mailenable Professional | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).
|
|||||
| CVE-2005-3392 | 1 Php | 1 Php | 2025-04-03 | 7.5 HIGH | N/A |
|
Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.
|
|||||
| CVE-2005-0769 | 1 Openslp | 1 Openslp | 2025-04-03 | 7.5 HIGH | N/A |
|
Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.
|
|||||
| CVE-2002-0736 | 1 Microsoft | 1 Backoffice | 2025-04-03 | 10.0 HIGH | N/A |
|
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
|
|||||
| CVE-2006-0687 | 1 Docmgr | 1 Docmgr | 2025-04-03 | 5.0 MEDIUM | N/A |
|
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.
|
|||||
| CVE-2006-1244 | 4 Debian, Gnome, Libextractor and 1 more | 4 Debian Linux, Gpdf, Libextractor and 1 more | 2025-04-03 | 7.6 HIGH | N/A |
|
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006 ...
Show More |
|||||
| CVE-2004-1379 | 1 Xine | 2 Xine, Xine-lib | 2025-04-03 | 7.5 HIGH | N/A |
|
Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first field.
|
|||||
| CVE-2002-0022 | 1 Microsoft | 1 Internet Explorer | 2025-04-03 | 7.5 HIGH | N/A |
|
Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.
|
|||||
| CVE-2005-2716 | 1 Nokia | 1 Affix | 2025-04-03 | 7.5 HIGH | N/A |
|
The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.
|
|||||
| CVE-2002-1276 | 1 Squirrelmail | 1 Squirrelmail | 2025-04-03 | 4.3 MEDIUM | N/A |
|
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.
|
|||||
| CVE-2003-0018 | 1 Linux | 1 Linux Kernel | 2025-04-03 | 3.6 LOW | N/A |
|
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.
|
|||||
| CVE-2005-1711 | 3 Clam Anti-virus, Gibraltar, Squid | 3 Clamav, Gibraltar Firewall, Squid | 2025-04-03 | 7.5 HIGH | N/A |
|
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.
|
|||||
| CVE-2003-1236 | 1 Tanne | 1 Tanne | 2025-04-03 | 10.0 HIGH | N/A |
|
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.
|
|||||
| CVE-2000-1093 | 1 Aol | 1 Instant Messenger | 2025-04-03 | 7.5 HIGH | N/A |
|
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.
|
|||||
| CVE-2006-2216 | 1 Devsyn | 1 Open Bulletin Board | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.
|
|||||
| CVE-2005-4708 | 1 Adobe | 9 Captivate, Contribute, Director and 6 more | 2025-04-03 | 7.2 HIGH | N/A |
|
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
|
|||||
| CVE-2005-1530 | 1 Sophos | 5 Sophos Anti-virus, Sophos Mailmonitor, Sophos Mailmonitor For Notes Domino and 2 more | 2025-04-03 | 5.0 MEDIUM | N/A |
|
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.
|
|||||
| CVE-2004-1911 | 1 Azerbaijan Development Group | 1 Azdgdating | 2025-04-03 | 4.3 MEDIUM | N/A |
|
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.
|
|||||