Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29868 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0796 2 Freebsd, Sgi 2 Freebsd, Irix 2025-04-03 5.0 MEDIUM N/A
SGI IRIX 6.5 through 6.5.12f and possibly earlier versions, and FreeBSD 3.0, allows remote attackers to cause a denial of service via a malformed IGMP multicast packet with a small response delay.
CVE-1999-1509 1 Etype 1 Eserv 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.
CVE-2003-0495 1 Ledscripts.com 1 Lednews 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.
CVE-2005-0796 1 Hola 1 Holacms 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.
CVE-2002-0565 1 Oracle 3 Application Server, Application Server Web Cache, Oracle9i 2025-04-03 5.0 MEDIUM N/A
Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
CVE-2000-0781 1 Ca 1 Arcserve Backup 2025-04-03 7.2 HIGH N/A
uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.
CVE-1999-0390 2 Redhat, Suse 2 Linux, Suse Linux 2025-04-03 7.2 HIGH N/A
Buffer overflow in Dosemu Slang library in Linux.
CVE-2000-1035 1 Typsoft 1 Typsoft 2025-04-03 10.0 HIGH N/A
Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.
CVE-2006-1897 1 Talentsoft 1 Web\+ Shop 2025-04-03 5.0 MEDIUM N/A
Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.
CVE-2001-0990 1 Inter7 1 Vpopmail 2025-04-03 4.6 MEDIUM N/A
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
CVE-2001-0518 1 Oracle 1 Oracle9i 2025-04-03 5.0 MEDIUM N/A
Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.
CVE-2006-2411 1 Raydium 1 Raydium 2025-04-03 7.5 HIGH N/A
Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client.
CVE-2006-4795 1 Hp 1 Hp-ux 2025-04-03 4.6 MEDIUM N/A
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.
CVE-2000-0654 1 Microsoft 1 Sql Server 2025-04-03 4.6 MEDIUM N/A
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
CVE-2005-0845 1 Netwin 1 Surgemail 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.
CVE-2006-1766 1 Papoo 1 Papoo 2025-04-03 6.4 MEDIUM N/A
Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php.
CVE-2001-0033 2 Kth, Netbsd 2 Kth Kerberos, Netbsd 2025-04-03 7.2 HIGH N/A
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.
CVE-2005-2696 1 Ibm 1 Lotus Notes 2025-04-03 5.0 MEDIUM N/A
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428.
CVE-2002-0011 1 Mozilla 1 Bugzilla 2025-04-03 5.0 MEDIUM N/A
Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.
CVE-2005-2583 1 Mentor 1 Adslfr4ii 2025-04-03 7.5 HIGH N/A
Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access.