Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29870 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4365 1 Flip 1 Flip 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.
CVE-2000-0323 1 Microsoft 1 Jet 2025-04-03 7.6 HIGH N/A
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
CVE-2000-0868 2 Apache, Suse 2 Http Server, Suse Linux 2025-04-03 5.0 MEDIUM N/A
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
CVE-2005-1241 1 Powertech 1 Powerlock Networksecurity 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.
CVE-2005-0216 1 Woltlab 1 Burning Board Lite 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter.
CVE-2005-4317 1 Limbo Cms 1 Limbo Cms 2025-04-03 6.8 MEDIUM N/A
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the stats module or (2) execute arbitrary code via an eval injection attack in the wrapper option in index2.php.
CVE-2004-0068 1 Phpdig.net 1 Phpdig 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.
CVE-1999-1433 1 Hp 1 Jetadmin 2025-04-03 7.2 HIGH N/A
HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.
CVE-2005-0012 1 Dillo 1 Dillo Web Browser 2025-04-03 7.5 HIGH N/A
Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.
CVE-2005-3187 1 Bluecoat 1 Winproxy 2025-04-03 5.0 MEDIUM N/A
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.
CVE-2005-4469 1 Phpgedview 1 Phpgedview 2025-04-03 7.5 HIGH N/A
Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, or the (2) user_language, (3) user_email, and (4) user_gedcomid parameters in login_register.php, which is directly inserted into authenticate.php.
CVE-2006-0970 1 Activecampaign 6 1-2-all, General, Isalient and 3 more 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
CVE-2000-1127 1 Hp 1 Hp-ux 2025-04-03 3.6 LOW N/A
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.
CVE-2003-0400 1 Vignette 3 Content Suite, Storyserver, Vignette 2025-04-03 5.0 MEDIUM N/A
Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.
CVE-2006-0098 1 Openbsd 1 Openbsd 2025-04-03 4.6 MEDIUM N/A
The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.
CVE-2000-0988 1 Bardon Data Systems 1 Winu 2025-04-03 7.2 HIGH N/A
WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.
CVE-2005-0960 1 Openbsd 1 Openbsd 2025-04-03 5.0 MEDIUM N/A
Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).
CVE-2003-0301 1 Microsoft 1 Outlook Express 2025-04-03 5.0 MEDIUM N/A
The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
CVE-2005-3828 1 Activecampaign 1 Knowledgebuilder 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.
CVE-2005-1189 1 Webcamxp 1 Webcamxp Pro 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.