Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0885 2 Caldera, Sun 3 Openunix, Unixware, Sunos 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.
CVE-2005-4334 1 John Andersson 1 Zixforum 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp.
CVE-2005-3132 2 Icewarp, Merak 2 Web Mail, Mail Server 2025-04-03 5.0 MEDIUM N/A
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
CVE-2001-1110 1 Khamil Landross And Zack Jones 1 Eftp 2025-04-03 5.0 MEDIUM N/A
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
CVE-2006-3166 1 Free Realty 1 Free Realty 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.
CVE-1999-0231 1 Seattle Lab Software 1 Slmail 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
CVE-2002-0682 1 Apache 1 Tomcat 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
CVE-2000-0629 1 Sun 1 Java System Web Server 2025-04-03 7.5 HIGH N/A
The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.
CVE-2005-4331 1 Ihtml Merchant 1 Ihtml Merchant 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.
CVE-2005-0622 1 Raidenhttpd 1 Raidenhttpd 2025-04-03 5.0 MEDIUM N/A
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.
CVE-2005-2464 1 Pcxp Toppe Cms 1 Pcxp Toppe Cms 2025-04-03 7.5 HIGH N/A
login.php in PCXP/TOPPE CMS allows remote attackers to bypass authentication and gain privileges by modifying the cookie to match the target userid.
CVE-2002-0944 1 Deepmetrix 1 Livestats 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.
CVE-2004-2482 1 Microsoft 1 Outlook 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
CVE-2006-1085 1 Php-stats 1 Php-stats 2025-04-03 10.0 HIGH N/A
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.
CVE-2000-0883 1 Mandrakesoft 1 Mandrake Linux 2025-04-03 5.0 MEDIUM N/A
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
CVE-2002-1771 1 Matt Wright 1 Formmail 2025-04-03 5.0 MEDIUM N/A
Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables.
CVE-2006-2705 1 Secure Elements 1 C5 Enterprise Vulnerability Management 2025-04-03 5.0 MEDIUM N/A
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.
CVE-2001-0984 1 Counterpane 1 Password Safe 2025-04-03 4.6 MEDIUM N/A
Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.
CVE-1999-0397 2025-04-03 10.0 HIGH N/A
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
CVE-2004-2104 1 Novell 1 Netware 2025-04-03 5.0 MEDIUM N/A
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.