Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1906 1 Jjgan852 1 Phplister 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2004-2474 1 Phpnews 1 Phpnews 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
CVE-2004-0066 1 Phpgedview 1 Phpgedview 2025-04-03 5.0 MEDIUM N/A
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.
CVE-2004-0906 1 Mozilla 2 Mozilla, Thunderbird 2025-04-03 4.6 MEDIUM N/A
The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.
CVE-2004-1187 3 Mandrakesoft, Mplayer, Xine 4 Mandrake Linux, Mplayer, Xine and 1 more 2025-04-03 10.0 HIGH N/A
Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
CVE-2005-1133 1 Ibm 1 Iseries As 400 2025-04-03 5.0 MEDIUM N/A
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
CVE-2001-0174 1 Trend Micro 1 Virus Buster 2001 2025-04-03 7.6 HIGH N/A
Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.
CVE-2003-0249 1 Php 1 Php 2025-04-03 7.5 HIGH N/A
PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.
CVE-1999-0081 1 Washington University 1 Wu-ftpd 2025-04-03 5.0 MEDIUM N/A
wu-ftp allows files to be overwritten via the rnfr command.
CVE-1999-0927 1 Gordano 1 Ntmail 2025-04-03 5.0 MEDIUM N/A
NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2006-2322 1 Cisco 2 Application Velocity System 3110, Application Velocity System 3120 2025-04-03 6.4 MEDIUM N/A
The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.
CVE-2005-0100 1 Gnu 2 Emacs, Xemacs 2025-04-03 7.5 HIGH N/A
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
CVE-2006-1559 1 Php 1 Php Script Index 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2000-0508 3 Debian, Mandrakesoft, Redhat 3 Debian Linux, Mandrake Linux, Linux 2025-04-03 5.0 MEDIUM N/A
rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.
CVE-2005-4035 1 Web4future 1 Web4future Ecommerce 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
CVE-2005-1368 1 Linux 1 Linux Kernel 2025-04-03 1.2 LOW N/A
The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.
CVE-2000-0223 1 Sam Hawker 1 Wmcdplay 2025-04-03 7.2 HIGH N/A
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.
CVE-2006-3085 1 Linux 1 Linux Kernel 2025-04-03 7.8 HIGH N/A
xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.
CVE-2003-1167 1 Gernot Stocker 1 Kpopup 2025-04-03 7.2 HIGH N/A
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.
CVE-2005-2599 1 Hummingbird 1 Connectivity 2025-04-03 7.5 HIGH N/A
Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.