Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29864 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1454 1 Macromedia 1 Matrix Screen Saver 2025-04-03 4.6 MEDIUM N/A
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.
CVE-2006-4886 1 Mcafee 2 Scan Engine, Virusscan Enterprise 2025-04-03 3.7 LOW N/A
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button, possibly due to an interface-related race condition.
CVE-2006-3796 1 Deluxebb 1 Deluxebb 2025-04-03 7.5 HIGH N/A
DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.
CVE-2005-0884 1 Digitalhive 1 Digitalhive 2025-04-03 7.5 HIGH N/A
DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script.
CVE-2004-1037 2 Gentoo, Twiki 2 Linux, Twiki 2025-04-03 10.0 HIGH N/A
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
CVE-2005-1948 1 Invision Power Services 1 Invision Gallery 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
CVE-2005-4013 1 Php Web 1 Statistik 2025-04-03 5.0 MEDIUM N/A
PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.
CVE-2006-0151 2 Todd Miller, Ubuntu 2 Sudo, Ubuntu Linux 2025-04-03 7.2 HIGH N/A
sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.
CVE-2004-1377 2 Gnu, Turbolinux 4 A2ps, Turbolinux Home, Turbolinux Server and 1 more 2025-04-03 2.1 LOW N/A
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2000-0573 1 Hp 1 Hp-ux 2025-04-03 10.0 HIGH N/A
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
CVE-2002-1855 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-0141 1 Maelstrom 1 Maelstrom Gpl 2025-04-03 1.2 LOW N/A
Maelstrom GPL 3.0.1 allows local users to overwrite arbitrary files of other Maelstrom users via a symlink attack on the /tmp/f file.
CVE-2002-1443 1 Google 1 Toolbar 2025-04-03 5.0 MEDIUM N/A
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.
CVE-2005-1855 2 Debian, Sukria 2 Debian Linux, Backup Manager 2025-04-03 2.1 LOW N/A
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
CVE-2002-0261 1 Instantservers Inc. 1 Miniportal 2025-04-03 7.5 HIGH N/A
Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.
CVE-2006-3905 1 Mywebland 1 Mybloggie 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote attackers to execute arbitrary SQL commands via the (1) post_id parameter in index.php and (2) search function.
CVE-2002-2032 1 Francisco Burzi 1 Php-nuke 2025-04-03 5.0 MEDIUM N/A
sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.
CVE-2006-1143 1 Ftpoed 1 Ftpoed Blog Engine 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment.
CVE-2005-0983 4 Activision, Id Software, Lucasarts and 1 more 10 Call Of Duty, Call Of Duty United Offensive, Return To Castle Wolfenstein and 7 more 2025-04-03 5.0 MEDIUM N/A
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.
CVE-2001-0829 1 Apache 1 Tomcat 2025-04-03 5.1 MEDIUM N/A
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.