Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2209 1 Pablo Software Solutions 1 Baby Ftp Server 2025-04-03 10.0 HIGH N/A
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
CVE-2000-0583 1 Inter7 1 Vpopmail Vchkpw 2025-04-03 5.0 MEDIUM N/A
vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.
CVE-2006-4191 1 Xmb Software 1 Extreme Message Board 2025-04-03 5.1 MEDIUM N/A
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
CVE-1999-0719 1 Gnu 1 Gnumeric 2025-04-03 4.6 MEDIUM N/A
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
CVE-2002-0604 1 Snapgear 1 Snapgear Lite\+ Firewall 2025-04-03 5.0 MEDIUM N/A
Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options.
CVE-2005-0034 1 Isc 1 Bind 2025-04-03 4.3 MEDIUM N/A
An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.
CVE-2002-0584 1 Workforceroi 1 Xpede 2025-04-03 5.0 MEDIUM N/A
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.
CVE-2005-3480 1 Ringtail 1 Casebook 2025-04-03 5.0 MEDIUM N/A
login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
CVE-2004-0710 1 Cisco 1 Ios 2025-04-03 5.0 MEDIUM N/A
IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.
CVE-2005-0784 1 Phorum 1 Phorum 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.
CVE-2005-3536 1 Phpbb Group 1 Phpbb 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
CVE-2002-1650 1 Squirrelmail 1 Squirrelmail 2025-04-03 7.5 HIGH N/A
The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter.
CVE-2002-1499 1 Factosystem 1 Factosystem Weblog 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.
CVE-1999-0786 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
CVE-2005-3098 1 Qualcomm 1 Qpopper 2025-04-03 4.6 MEDIUM N/A
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.
CVE-2004-1604 1 Cpanel 1 Cpanel 2025-04-03 5.0 MEDIUM N/A
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.
CVE-2006-3696 1 Agnitum 1 Outpost Firewall 2025-04-03 2.1 LOW N/A
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe.
CVE-2002-2124 1 Nylon 1 Nylon 2025-04-03 5.0 MEDIUM N/A
The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.
CVE-2005-2805 1 E107 1 E107 2025-04-03 5.0 MEDIUM N/A
forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.
CVE-2003-0460 1 Apache 1 Http Server 2025-04-03 5.0 MEDIUM N/A
The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.