Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4572 1 Myezshop 1 Myezshop Shopping Cart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-2190 1 Comersus Open Technologies 1 Comersus Cart 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.
CVE-2006-0695 1 Ansilove 1 Ansilove 2025-04-03 7.5 HIGH N/A
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.
CVE-2005-0047 1 Microsoft 3 Windows 2000, Windows 2003 Server, Windows Xp 2025-04-03 7.2 HIGH N/A
Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."
CVE-2006-1862 1 Linux 1 Linux Kernel 2025-04-03 4.9 MEDIUM N/A
The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.
CVE-2005-0310 1 Exponent 1 Exponent 2025-04-03 5.0 MEDIUM N/A
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.
CVE-2006-1579 1 Dbbs 1 Dbbs 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter.
CVE-2003-1021 1 Sco 1 Openserver 2025-04-03 7.2 HIGH N/A
The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.
CVE-2003-0325 1 Ambrosia Software 1 Maelstrom 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
CVE-2002-0470 1 Phpnettoolpack 1 Phpnettoolpack 2025-04-03 7.2 HIGH N/A
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path.
CVE-2004-1542 1 Raven Software 1 Soldier Of Fortune 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.
CVE-2005-0176 1 Linux 1 Linux Kernel 2025-04-03 5.0 MEDIUM N/A
The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.
CVE-1999-0737 1 Microsoft 1 Internet Information Server 2025-04-03 5.0 MEDIUM N/A
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-2006-0368 1 Cisco 1 Call Manager 2025-04-03 7.8 HIGH N/A
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
CVE-2001-1478 1 Caldera 2 Openunix, Unixware 2025-04-03 7.2 HIGH N/A
Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code.
CVE-2003-0602 1 Mozilla 1 Bugzilla 2025-04-03 6.8 MEDIUM N/A
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
CVE-2005-0230 1 Mozilla 1 Firefox 2025-04-03 5.1 MEDIUM N/A
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
CVE-2000-0427 1 Aladdin Knowledge Systems 1 Etoken 2025-04-03 4.6 MEDIUM N/A
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.
CVE-2005-0522 1 Lionmax Software 1 Chat Anywhere 2025-04-03 4.6 MEDIUM N/A
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
CVE-2001-0619 1 Lucent 1 Orinoco 2025-04-03 7.5 HIGH N/A
The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.