Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29860 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2153 1 Jbmc Software 1 Directadmin 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin Hosting Management allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
CVE-1999-0641 2025-04-03 N/A N/A
The UUCP service is running.
CVE-2004-2106 1 Novell 1 Netware 2025-04-03 5.0 MEDIUM N/A
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.
CVE-2003-0718 1 Microsoft 2 Internet Information Server, Internet Information Services 2025-04-03 5.0 MEDIUM N/A
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.
CVE-2005-0808 1 Apache 1 Tomcat 2025-04-03 5.0 MEDIUM N/A
Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
CVE-2000-0706 1 Luca Deri 1 Ntop 2025-04-03 10.0 HIGH N/A
Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.
CVE-2002-1084 1 Visualshapers 1 Ezcontents 2025-04-03 6.4 MEDIUM N/A
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.
CVE-1999-1037 1 Coast 1 Satan 2025-04-03 7.2 HIGH N/A
rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.
CVE-2004-2244 1 Oracle 2 Application Server, Oracle9i 2025-04-03 5.0 MEDIUM N/A
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
CVE-2001-1448 1 Magic 1 Edeveloper 2025-04-03 4.6 MEDIUM N/A
Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.
CVE-1999-1437 1 Ralf S. Engelschall 1 Eperl 2025-04-03 7.5 HIGH N/A
ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.
CVE-2005-0613 1 Fckeditor 1 Fckeditor 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
CVE-2000-0638 1 Sean Macguire 1 Big Brother 2025-04-03 10.0 HIGH N/A
bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.
CVE-2006-1967 1 Kcscripts 2 Kcscripts Calendar, Portal Pack 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.
CVE-2006-2865 1 Phpbb Group 1 Phpbb 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a mod
CVE-2005-1357 1 Text.cgi 1 Text.cgi 2025-04-03 5.0 MEDIUM N/A
text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-1999-0626 1 Sun 1 Rpc.ruserd 2025-04-03 N/A N/A
A version of rusers is running that exposes valid user information to any entity on the network.
CVE-1999-0584 2025-04-03 10.0 HIGH N/A
A Windows NT file system is not NTFS.
CVE-2006-4545 1 Modulebased Cms 1 Modulebased Cms 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter in (1) admin/avatar.php, (2) libs/archive.class.php, (3) libs/login.php, (4) libs/profiles.class.php, and (5) libs/profile/proccess.php. NOTE: CVE disputes this claim, as the _SERVER array and the _SERVER[DOCUMENT_ROOT] index are controlled by PHP and cannot be manipulated by an attacker
CVE-2005-2724 1 Inter7 1 Sqwebmail 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.