Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29862 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2808 1 Lycos 1 Htmlgear Guestgear 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Lycos Tripod htmlGEAR guestGEAR (aka Guest Gear) allows remote attackers to inject arbitrary web script or HTML via a guestbook post containing a javascript URI in the SRC attribute of the BR element after an extra "iframe" tagname within that element, followed by a double ">", which might bypass cleansing operations.
CVE-2005-3695 1 Litespeed Technologies 1 Litespeed Web Server 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
CVE-2001-1413 1 Ncompress 1 Ncompress 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
CVE-2006-1893 1 Ar-blog 1 Ar-blog 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2005-1083 1 Aewebworks 1 Aedating 2025-04-03 5.0 MEDIUM N/A
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.
CVE-2006-2037 1 Thwboard 1 Thwboard 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter.
CVE-2003-0202 1 Brian Renaud 1 Metrics 2025-04-03 4.6 MEDIUM N/A
The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2004-0538 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 7.5 HIGH N/A
LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.
CVE-2002-0993 1 Hp 1 Instant Support 2025-04-03 4.6 MEDIUM N/A
Unknown vulnerability in HP Instant Support Enterprise Edition (ISEE) product U2512A for HP-UX 11.00 and 11.11 may allow authenticated users to access restricted files.
CVE-2000-0425 1 Lsoft 1 Listserv 2025-04-03 10.0 HIGH N/A
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
CVE-2006-2756 1 Eitsop 1 My Web Server 2025-04-03 5.0 MEDIUM N/A
Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request. NOTE: CVE analysis suggests that this is a different product, and therefore a different vulnerability, than CVE-2002-1897.
CVE-2005-4433 1 Esselbach Internet Solutions 1 Esselbach Storyteller Cms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in Esselbach Storyteller CMS 1.8 allows remote attackers to inject arbitrary web script or HTML via the query parameter, which is used by the Search field.
CVE-2005-4028 1 Amember 1 Amember 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php.
CVE-2005-0998 1 Francisco Burzi 1 Php-nuke 2025-04-03 5.0 MEDIUM N/A
The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.
CVE-2005-1584 1 Open Solution 1 Quick.forum 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.
CVE-2002-1952 1 Phprank 1 Phprank 2025-04-03 7.5 HIGH N/A
phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.
CVE-1999-1132 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.
CVE-2004-2098 1 Native Solutions 1 Tbe Banner Engine 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.
CVE-2005-1571 1 Wenig And Spitzer-williams 1 Showoff Digital Media Software 2025-04-03 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic scripts.
CVE-2006-4761 1 Luke Hutteman 1 Sharpreader 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Luke Hutteman SharpReader allow remote attackers to inject arbitrary web script or HTML via a web feed, as demonstrated by certain test cases of the Robert Auger and Caleb Sima RSS and Atom feed reader test suite.