Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29867 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1989 1 Caucho Technology 1 Resin 2025-04-03 5.0 MEDIUM N/A
Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.
CVE-2006-4788 1 Telekorn 1 Signkorn Guestbook 2025-04-03 5.1 MEDIUM N/A
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
CVE-2005-2573 2 Mysql, Oracle 2 Mysql, Mysql 2025-04-03 5.0 MEDIUM N/A
The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.
CVE-2004-1438 1 Subversion 1 Subversion 2025-04-03 2.1 LOW N/A
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
CVE-2005-3951 1 Php Labs 1 Survey Wizard 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-2000-0655 2 Mozilla, Netscape 2 Mozilla, Communicator 2025-04-03 5.0 MEDIUM N/A
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
CVE-2005-2435 1 Website Baker 1 Website Baker 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
CVE-2000-0378 1 Redhat 1 Linux 2025-04-03 7.2 HIGH N/A
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
CVE-2003-1190 1 Phprecipebook 1 Phprecipebook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.
CVE-2003-0473 1 Sgi 1 Irix 2025-04-03 10.0 HIGH N/A
Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.
CVE-2002-0521 1 Asp-nuke 1 Asp-nuke 2025-04-03 5.1 MEDIUM N/A
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp.
CVE-2004-0086 1 Apple 1 Mac Os X 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
CVE-2000-0035 1 Great Circle Associates 1 Majordomo 2025-04-03 4.6 MEDIUM N/A
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
CVE-2004-0148 2 Sgi, Washington University 2 Propack, Wu-ftpd 2025-04-03 7.2 HIGH N/A
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
CVE-2002-0213 2 Sgi, Xinet 2 Irix, K-ashare 2025-04-03 2.1 LOW N/A
xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
CVE-2005-0255 1 Mozilla 3 Firefox, Mozilla, Thunderbird 2025-04-03 5.0 MEDIUM N/A
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.
CVE-2004-2377 1 Alcatel 2 Omniswitch, Omniswitch 7800 2025-04-03 5.0 MEDIUM N/A
Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.
CVE-2005-3379 1 Trend Micro 2 Officescan, Pc-cillin 2005 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in Trend Micro (1) PC-Cillin 2005 12.0.1244 with the 7.510.1002 engine and (2) OfficeScan 7.0 with the 7.510.1002 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
CVE-2006-2710 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 5.0 MEDIUM N/A
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications.
CVE-1999-0270 1 Sgi 1 Irix 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.