Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29862 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3134 1 Citrix 1 Metaframe 2025-04-03 7.5 HIGH N/A
Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).
CVE-2004-1933 1 Citadel 1 Ux 2025-04-03 2.1 LOW N/A
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.
CVE-2006-3051 1 Six Offene Systeme Gmbh 1 Sixcms 2025-04-03 5.1 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.
CVE-2001-0189 1 Intranet-server 1 Localweb2000 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.
CVE-2002-1723 1 Powerboards 1 Powerboards 2025-04-03 5.0 MEDIUM N/A
Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message.
CVE-2002-0645 1 Microsoft 2 Data Engine, Sql Server 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
CVE-2001-0865 1 Cisco 1 12000 Router 2025-04-03 7.5 HIGH N/A
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.
CVE-2004-1109 1 Kerio 1 Personal Firewall 2025-04-03 5.0 MEDIUM N/A
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.
CVE-2005-4390 1 Contentserv 1 Contentserv 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.
CVE-2002-0947 1 Oracle 2 Application Server, Reports 2025-04-03 7.5 HIGH N/A
Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.
CVE-2005-1577 1 Apg Technology 1 Classmaster 2025-04-03 7.5 HIGH N/A
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.
CVE-2002-1319 2 Linux, Trustix 2 Linux Kernel, Secure Linux 2025-04-03 2.1 LOW N/A
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
CVE-2005-3752 1 Ldapdiff 1 Ldapdiff 2025-04-03 10.0 HIGH N/A
Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction".
CVE-2002-0374 1 Padl Software 1 Pam Ldap 2025-04-03 7.5 HIGH N/A
Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.
CVE-2002-0996 1 Novell 2 Netmail, Netmail Xe 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.
CVE-2006-4305 2 Mysql, Sap-db 2 Maxdb, Sap-db 2025-04-03 10.0 HIGH N/A
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.
CVE-2004-2607 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.
CVE-2004-1898 1 Tildeslash 1 Monit 2025-04-03 10.0 HIGH N/A
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
CVE-2001-1499 1 Checkpoint 1 Vpn-1 2025-04-03 5.0 MEDIUM N/A
Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.
CVE-2006-4119 1 Chaossoft 1 Geheimchaos 2025-04-03 5.1 MEDIUM N/A
SQL injection vulnerability in gc.php in GeheimChaos 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the Temp_entered_password parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.