Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29862 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2190 1 Unzoo 1 Unzoo 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Unzoo 4.4-2 has unknown impact and attack vectors.
CVE-2002-1973 2 Microsoft, Working Resources Inc. 2 Foundation Class Library, Badblue 2025-04-03 7.5 HIGH N/A
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
CVE-2002-1100 1 Cisco 2 Vpn 3000 Concentrator Series Software, Vpn 3002 Hardware Client 2025-04-03 5.0 MEDIUM N/A
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.
CVE-1999-1163 1 Hp 1 9000 2025-04-03 7.5 HIGH N/A
Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.
CVE-2006-2509 1 Yourfreeworld 1 Short Url And Url Tracker Script 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in login.php in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-3369 1 Iduprey 1 Kamikaze-qscm 2025-04-03 5.0 MEDIUM N/A
Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.
CVE-2005-1822 1 Qualiteam 1 X-cart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.
CVE-1999-1585 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
CVE-1999-1558 1 Digital 2 Digital Openvms, Digital Openvms Axp 2025-04-03 7.5 HIGH N/A
Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.
CVE-2005-3595 1 Microsoft 1 Windows Xp 2025-04-03 10.0 HIGH N/A
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.
CVE-2006-2364 1 Macromedia 1 Coldfusion 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message.
CVE-2003-0333 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
CVE-2006-2500 1 Xfairguy 1 Codeavalanche News 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field. NOTE: if this issue is limited to administrators, and if it is expected behavior for administrators to be able to generate HTML, then this is not a vulnerability.
CVE-2004-1281 1 Junkie 1 Junkie Ftp Client 2025-04-03 5.0 MEDIUM N/A
The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.
CVE-1999-0734 1 Cisco 1 Ciscosecure 2025-04-03 7.5 HIGH N/A
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
CVE-2005-0934 1 Wackowiki 1 Wackowiki 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-1999-0253 1 Microsoft 2 Internet Information Server, Internet Information Services 2025-04-03 7.5 HIGH N/A
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
CVE-2003-0559 1 Phpforum 1 Phpforum 2025-04-03 7.5 HIGH N/A
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.
CVE-2006-1691 1 Manic Web 1 Mwnewsletter 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php.
CVE-2001-0336 1 Microsoft 1 Internet Information Server 2025-04-03 5.0 MEDIUM N/A
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.