Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0172 1 Matt Wright 1 Formmail 2025-04-03 7.5 HIGH N/A
FormMail CGI program allows remote execution of commands.
CVE-2006-2278 1 Arabless 1 Saphplesson 2025-04-03 5.0 MEDIUM N/A
SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow parameter to (c) showcat.php; or the (3) rows parameter to index.php.
CVE-2001-1075 1 Sun 1 Cobalt Raq 3i 2025-04-03 5.0 MEDIUM N/A
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file.
CVE-2000-1085 1 Microsoft 2 Data Engine, Sql Server 2025-04-03 4.6 MEDIUM N/A
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
CVE-2002-1433 1 Kerio 1 Kerio Mailserver 2025-04-03 5.0 MEDIUM N/A
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
CVE-2005-4651 1 Alstrasoft 1 Epay 2025-04-03 6.4 MEDIUM N/A
SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.
CVE-2004-0238 1 0verkill 1 0verkill 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.
CVE-2004-0544 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
CVE-2006-4762 1 Rssreader 1 Rssreader 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Ykoon RssReader allow remote attackers to inject arbitrary web script or HTML via a web feed, as demonstrated by certain test cases of the Robert Auger and Caleb Sima RSS and Atom feed reader test suite.
CVE-2002-2173 1 Cerulean Studios 1 Trillian 2025-04-03 7.5 HIGH N/A
Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message.
CVE-2002-1523 1 Daniel Arenz 1 Mini Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) ..\ (dot-dot backslash) sequences.
CVE-1999-0267 1 Ncsa 1 Ncsa Httpd 2025-04-03 7.5 HIGH N/A
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
CVE-1999-1318 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.
CVE-1999-1432 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
CVE-2005-3168 1 Microsoft 1 Windows 2000 2025-04-03 7.5 HIGH N/A
The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
CVE-2000-0940 1 Metertek 1 Pagelog.cgi 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
CVE-2004-1145 7 Altlinux, Conectiva, Debian and 4 more 9 Alt Linux, Linux, Debian Linux and 6 more 2025-04-03 5.0 MEDIUM N/A
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
CVE-2006-2954 1 Primoris Software 1 Officeflow 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.
CVE-2001-1194 1 Zyxel 2 Prestige 1600, Prestige 681 2025-04-03 5.0 MEDIUM N/A
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly.
CVE-1999-0044 1 Sgi 1 Irix 2025-04-03 7.2 HIGH N/A
fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.