Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Angry Yack Logo
Total 29869 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0588 1 Sco 1 Openserver 2025-04-03 4.6 MEDIUM N/A
sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.
CVE-2005-3159 1 Php Fusion 1 Php Fusion 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
CVE-2005-3925 1 Helpdesk Issue Manager 1 Helpdesk Issue Manager 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
CVE-2006-2719 1 Jiwa 1 Financials 2025-04-03 4.9 MEDIUM N/A
JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.
CVE-2005-2785 1 Cosmoshop 1 Cosmoshop 2025-04-03 2.1 LOW N/A
cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.
CVE-2005-2557 3 Debian, Gentoo, Mantis 3 Debian Linux, Linux, Mantis 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.
CVE-2006-2314 1 Postgresql 1 Postgresql 2025-04-03 7.5 HIGH N/A
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Bas ...

Show More

CVE-2006-2491 2 Boastmachine, Kailash Nadh 2 Boastmachine, Boastmachine 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
CVE-2002-0569 1 Oracle 1 Application Server 2025-04-03 7.5 HIGH N/A
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
CVE-2001-0281 1 Microsoft 1 Windows Nt 2025-04-03 7.2 HIGH N/A
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
CVE-2001-0224 1 Brightstation 1 Muscat Empower 2025-04-03 5.0 MEDIUM N/A
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
CVE-2005-4821 1 Neocrome 1 Land Down Under 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
CVE-2006-4781 1 Futuresoft 1 Tftp Server Multithreaded 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained from third party information.
CVE-2002-0230 1 Faq-o-matic 1 Faq-o-matic 2025-04-03 5.0 MEDIUM N/A
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.
CVE-2002-1815 1 Aquonics Scripting 1 Aquonics File Manager 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in source.php and source.cgi in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
CVE-2003-1214 1 Visualshapers 1 Ezcontents 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.
CVE-2002-1239 1 Qnx 1 Rtos 2025-04-03 7.2 HIGH N/A
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.
CVE-2002-1948 1 Gringotts 1 Gringotts 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.
CVE-1999-1315 1 Dec 1 Dec Openvms 2025-04-03 4.6 MEDIUM N/A
Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.
CVE-2006-4779 1 Phpbb Group 1 Vitrax Premodded Phpbb 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
CVE-2005-0595 1 Working Resources Inc. 1 Badblue 2025-04-03 7.5 HIGH N/A
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
CVE-2005-1694 1 Postnuke Software Foundation 1 Postnuke 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.
CVE-2005-3871 1 Jbb 1 Jbb 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) forum and (3) zeigeseite parameters in showforum.php, (4) forum parameter in newtopic.php, and (5) tidnr parameter in neuerbeitrag.php.
CVE-2000-1018 1 Mendel Cooper 1 Shred 2025-04-03 2.1 LOW N/A
shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file.
CVE-2005-2319 1 Yawp 1 Yawp 2025-04-03 5.0 MEDIUM N/A
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.
CVE-2005-0019 1 Yongguang Zhang 1 Hztty 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.
CVE-2001-1106 1 Sambar 1 Sambar Server 2025-04-03 7.5 HIGH N/A
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
CVE-2004-0558 1 Easy Software Products 1 Cups 2025-04-03 5.0 MEDIUM N/A
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.
CVE-2005-2814 1 Flatnuke 1 Flatnuke 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
CVE-2003-1299 1 Pablo Software Solutions 1 Baby Ftp Server 2025-04-03 4.0 MEDIUM N/A
Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.
CVE-2004-2065 1 Daniel Barron 1 Dansguardian 2025-04-03 7.5 HIGH N/A
DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.
CVE-2005-4605 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.
CVE-2005-2180 1 Gnu 1 Gnats 2025-04-03 2.1 LOW N/A
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
CVE-2001-0291 2025-04-03 10.0 HIGH N/A
Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.
CVE-2005-2217 1 Craig Dansie 1 Dansie Shopping Cart 2025-04-03 5.0 MEDIUM N/A
Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.
CVE-2005-3286 1 Kerio 2 Personal Firewall, Serverfirewall 2025-04-03 2.1 LOW N/A
The FWDRV driver in Kerio Personal Firewall 4.2 and Server Firewall 1.1.1 allows local users to cause a denial of service (crash) by setting the PAGE_NOACCESS or PAGE_GUARD protection on the Page Environment Block (PEB), which triggers an exception, aka the "PEB lockout vulnerability."
CVE-1999-0251 1 Talkd 1 Talkd 2025-04-03 5.0 MEDIUM N/A
Denial of service in talk program allows remote attackers to disrupt a user's display.
CVE-2001-0663 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 5.0 MEDIUM N/A
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
CVE-2004-2290 1 Microsoft 1 Windows Xp 2025-04-03 7.5 HIGH N/A
Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder.
CVE-2006-0384 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".