Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29867 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0845 1 Leif M. Wright 1 Web Blog 2025-04-03 6.5 MEDIUM N/A
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
CVE-2002-1070 1 Php-wiki 1 Php-wiki 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
CVE-2002-2370 1 Sws 1 Sws Simple Web Server 2025-04-03 5.0 MEDIUM N/A
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
CVE-1999-1070 1 Xylogics 1 Annex 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.
CVE-2005-3742 1 Advanced Poll 1 Advanced Poll 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.
CVE-1999-1471 1 Bsd 1 Bsd 2025-04-03 7.2 HIGH N/A
Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.
CVE-2002-2122 1 Pointsec Mobile Technologies 1 Pointsec 2025-04-03 2.1 LOW N/A
Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory.
CVE-2005-0150 1 Mozilla 1 Firefox 2025-04-03 5.0 MEDIUM N/A
Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
CVE-2005-4763 1 Bea 1 Weblogic Server 2025-04-03 7.5 HIGH N/A
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) is used, sometimes include a password in an exception message that is sent to a client or stored in a log file, which might allow remote attackers to perform unauthorized actions.
CVE-2005-2783 1 Php Fusion 1 Php Fusion 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
CVE-1999-1088 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
CVE-2003-0304 1 Oneorzero 1 Oneorzero Helpdesk 2025-04-03 10.0 HIGH N/A
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.
CVE-2004-2624 1 Wackowiki 1 Wackowiki 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter.
CVE-1999-0943 1 Openlink 1 Openlink 2025-04-03 10.0 HIGH N/A
Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.
CVE-2006-0544 1 Microsoft 1 Ie 2025-04-03 7.5 HIGH N/A
urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
CVE-2001-0978 1 Hp 1 Hp-ux 2025-04-03 7.5 HIGH N/A
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.
CVE-1999-1338 1 Delegate 1 Delegate 2025-04-03 5.0 MEDIUM N/A
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
CVE-2006-4552 1 Chxo 1 Feedsplitter 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed.
CVE-2006-1578 1 Index Data Aps 1 Keystone Digital Library Suite 2025-04-03 6.4 MEDIUM N/A
Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.
CVE-2002-1086 1 Visualshapers 1 Ezcontents 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.