Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29864 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0994 1 Sun 1 Sun Pci Ii Driver 2025-04-03 7.5 HIGH N/A
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.
CVE-2001-0845 1 Dec 4 Dec Openvms, Dec Openvms Alpha, Sevms and 1 more 2025-04-03 4.6 MEDIUM N/A
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.
CVE-2005-2110 1 Wordpress 1 Wordpress 2025-04-03 5.0 MEDIUM N/A
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
CVE-2001-1361 1 Twig Development Team 1 Twig 2025-04-03 7.5 HIGH N/A
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.
CVE-2006-2155 1 Emc 1 Retrospect 2025-04-03 4.6 MEDIUM N/A
EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper file permissions.
CVE-2006-4162 1 Cpg-nuke 1 Dragonfly Cms 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Dragonfly CMS 9.0.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search field.
CVE-2000-0683 1 Bea 1 Weblogic Server 2025-04-03 5.0 MEDIUM N/A
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.
CVE-2003-1132 1 Cisco 2 Content Services Switch 11000, Content Services Switch 11500 2025-04-03 5.0 MEDIUM N/A
The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.
CVE-2004-0094 1 Xfree86 Project 1 X11r6 2025-04-03 7.5 HIGH N/A
Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).
CVE-2004-2614 1 Xuebrothers 1 Myweb 2025-04-03 7.5 HIGH N/A
Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
CVE-2005-1544 1 Libtiff 1 Libtiff 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
CVE-2005-2126 1 Microsoft 4 Ie, Windows 2000, Windows 2003 Server and 1 more 2025-04-03 2.6 LOW N/A
The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.
CVE-2006-0113 1 Enhanced Simple Php Gallery 1 Enhanced Simple Php Gallery 2025-04-03 5.0 MEDIUM N/A
Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.
CVE-2004-0426 1 Andrew Tridgell 1 Rsync 2025-04-03 5.0 MEDIUM N/A
rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.
CVE-2006-3559 1 Arif Supriyanto 1 Auracms 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.
CVE-1999-0800 1 Allaire 1 Forums 2025-04-03 5.0 MEDIUM N/A
The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.
CVE-2006-3075 1 Picturedis 2 Picturedis Photoalbum, Picturedis Professional 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in PictureDis Professional 1.33 Build 234 and earlier and PictureDis Photoalbum 4.82 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to files in photoalbum/ including (1) thumstbl.php, (2) wpfiles.php, and (3) wallpapr.php.
CVE-1999-1580 2 Sendmail, Sun 2 Sendmail, Sunos 2025-04-03 7.2 HIGH N/A
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
CVE-1999-1220 1 Great Circle Associates 1 Majordomo 2025-04-03 7.5 HIGH N/A
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
CVE-1999-0342 1 Pam 1 Pam 2025-04-03 6.2 MEDIUM N/A
Linux PAM modules allow local users to gain root access using temporary files.