Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29863 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1756 1 Matthew Dingley 1 Md News 2025-04-03 7.5 HIGH N/A
MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area.
CVE-2005-2962 1 Ntlmaps 1 Ntlmaps 2025-04-03 2.1 LOW N/A
The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.
CVE-2005-3795 1 Alstrasoft 1 Affiliate Network Pro 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php and the (2) firstname and (3) lastname parameters in index.php.
CVE-2006-0433 1 Freebsd 1 Freebsd 2025-04-03 5.0 MEDIUM N/A
Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).
CVE-2002-0050 1 Microsoft 1 Commerce Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
CVE-2006-3828 1 Kailash Nadh 1 Boastmachine 2025-04-03 6.5 MEDIUM N/A
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
CVE-2005-0712 1 Apple 1 Mac Os X 2025-04-03 4.6 MEDIUM N/A
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
CVE-2005-4212 1 Coinsoft Technologies 1 Phpcoin 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.
CVE-2006-2352 1 Ipswitch 1 Whatsup Professional 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-1999-0338 1 Ibm 1 Aix 2025-04-03 7.2 HIGH N/A
AIX Licensed Program Product performance tools allow local users to gain root access.
CVE-2006-3536 1 Ej3 1 Topo 2025-04-03 7.5 HIGH N/A
Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbitrary PHP code via parameters such as (1) descripcion and (2) pais, which are stored directly in a PHP script. NOTE: the provenance of this information is unknown; the details are obtained solely from third party reports.
CVE-2006-1835 1 Vincent Hor 2 Calendarix, Calendarix Advanced 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.
CVE-2005-2207 1 Elemental Software 1 Cartwiz 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVE-2005-1830 1 Compuware 1 Softice Driverstudio 2025-04-03 5.0 MEDIUM N/A
The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.
CVE-2005-1869 1 Appindex 1 Mwchat 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter.
CVE-2004-2060 1 Xlinesoft 1 Asprunner 2025-04-03 5.0 MEDIUM N/A
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
CVE-2003-0581 1 Xfstt 1 Xfstt 2025-04-03 7.5 HIGH N/A
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access.
CVE-2003-1044 1 Mozilla 1 Bugzilla 2025-04-03 7.5 HIGH N/A
editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
CVE-2004-0976 1 Larry Wall 1 Perl 2025-04-03 2.1 LOW N/A
Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
CVE-2006-2142 1 Limbo Cms 1 Limbo Cms 2025-04-03 6.4 MEDIUM N/A
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.