Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2421 1 Beehive Forum 1 Beehive Forum 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.
CVE-2005-0429 1 Jelsoft 1 Vbulletin 2025-04-03 5.0 MEDIUM N/A
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
CVE-2004-0110 2 Sgi, Xmlsoft 3 Propack, Libxml, Libxml2 2025-04-03 7.5 HIGH N/A
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
CVE-2005-1747 2 Bea, Oracle 2 Weblogic Server, Weblogic Portal 2025-04-03 6.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.
CVE-2004-1855 1 Mythic Entertainment 1 Dark Age Of Camelot 2025-04-03 5.0 MEDIUM N/A
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
CVE-2004-0548 2 Gentoo, Gnu 2 Linux, Aspell 2025-04-03 7.2 HIGH N/A
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.
CVE-2005-1738 1 Iron Bars Shell 1 Iron Bars Shell 2025-04-03 10.0 HIGH N/A
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.
CVE-2000-0473 1 Analogx 1 Simpleserver Www 2025-04-03 7.5 HIGH N/A
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.
CVE-2004-0576 1 Gnu 1 Radius 2025-04-03 5.0 MEDIUM N/A
The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.
CVE-1999-0279 1 Excite 1 Ews 2025-04-03 7.5 HIGH N/A
Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.
CVE-2005-2768 1 Sophos 1 Sophos Anti-virus 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.
CVE-1999-0004 3 Hp, Sco, University Of Washington 3 Dtmail, Unixware, Pine 2025-04-03 5.0 MEDIUM N/A
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
CVE-2005-3043 1 Mall23 1 Mall23 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.
CVE-1999-0526 1 X.org 1 X11 2025-04-03 10.0 HIGH N/A
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
CVE-2004-1375 1 Hp 1 Hp-ux 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.
CVE-1999-1451 1 Microsoft 2 Internet Information Server, Site Server 2025-04-03 5.0 MEDIUM N/A
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
CVE-2000-0801 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.
CVE-2006-0708 1 Nullsoft 1 Winamp 2025-04-03 9.3 HIGH N/A
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
CVE-2000-0175 1 Sun 1 Staroffice 2025-04-03 10.0 HIGH N/A
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
CVE-2000-0146 1 Novell 1 Groupwise 2025-04-03 5.0 MEDIUM N/A
The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.