Vulnerabilities (CVE)

Filtered by CWE-20
Total 11775 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2177 1 Net-snmp 1 Net-snmp 2025-04-03 5.0 MEDIUM N/A
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
CVE-2005-3678 1 Google 1 Talk 2025-04-03 5.0 MEDIUM N/A
Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.
CVE-2004-2533 1 Solarwinds 1 Serv-u File Server 2025-04-03 5.0 MEDIUM N/A
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.
CVE-2005-2806 1 Trevor Hogan 1 Bnbt 2025-04-03 5.0 MEDIUM N/A
client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.
CVE-2002-2322 1 Ultimate Php Board 1 Ultimate Php Board 2025-04-03 5.0 MEDIUM N/A
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.
CVE-2006-2223 1 Quagga 1 Quagga 2025-04-03 5.0 MEDIUM N/A
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.
CVE-2006-1858 1 Linux 1 Linux Kernel 2025-04-03 7.8 HIGH N/A
SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.
CVE-1999-0726 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 7.8 HIGH N/A
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
CVE-2006-1626 1 Microsoft 2 Internet Explorer, Windows Xp 2025-04-03 4.3 MEDIUM N/A
Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: this is a different vulnerability than CVE-2006-1192.
CVE-2003-1487 1 Phorum 1 Phorum 2025-04-03 10.0 HIGH N/A
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.
CVE-2004-1125 3 Easy Software Products, Kde, Xpdf 3 Cups, Kde, Xpdf 2025-04-03 9.3 HIGH N/A
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
CVE-2005-1787 1 Phpstat 1 Phpstat 2025-04-03 7.5 HIGH N/A
setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.
CVE-2003-0567 1 Cisco 3 Ios, Ons 15454 Optical Transport Platform, Optical Networking Systems Software 2025-04-03 7.8 HIGH N/A
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.
CVE-2006-3014 1 Microsoft 1 Excel 2025-04-03 5.1 MEDIUM N/A
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.
CVE-2006-1729 2 Canonical, Mozilla 4 Ubuntu Linux, Firefox, Mozilla Suite and 1 more 2025-04-03 4.3 MEDIUM N/A
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
CVE-2000-0258 1 Microsoft 2 Internet Information Server, Internet Information Services 2025-04-03 5.0 MEDIUM 7.5 HIGH
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
CVE-2003-1364 1 Aprelium Technologies 1 Abyss Web Server 2025-04-03 8.5 HIGH N/A
Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.
CVE-2003-1419 1 Netscape 1 Navigator 2025-04-03 4.3 MEDIUM N/A
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
CVE-2000-0400 1 Microsoft 1 Internet Explorer 2025-04-03 7.5 HIGH N/A
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.
CVE-2006-2782 1 Mozilla 2 Firefox, Seamonkey 2025-04-03 4.3 MEDIUM N/A
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.