Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0483 1 Francisco Burzi 1 Php-nuke 2025-04-03 5.0 MEDIUM N/A
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
CVE-2003-1309 1 Zonelabs 1 Zonealarm 2025-04-03 10.0 HIGH N/A
The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").
CVE-2000-1203 1 Lotus 1 Domino 2025-04-03 5.0 MEDIUM N/A
Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.
CVE-2006-1090 1 Punbb 1 Punbb 2025-04-03 7.8 HIGH N/A
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.
CVE-2005-1288 1 Asp Press 1 Acs Blog 2025-04-03 7.5 HIGH N/A
inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.
CVE-2000-1012 1 Freebsd 1 Freebsd 2025-04-03 7.2 HIGH N/A
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
CVE-2005-0653 1 Phpmyadmin 1 Phpmyadmin 2025-04-03 4.6 MEDIUM N/A
phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.
CVE-2005-3951 1 Php Labs 1 Survey Wizard 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-2002-1407 1 Adam Megacz 1 Tinyssl 2025-04-03 7.5 HIGH N/A
TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
CVE-2005-0950 1 Faststone 1 4in1 Browser 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.
CVE-2004-2457 1 3com 1 3crwe754g72-a 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.
CVE-2006-0986 1 Wordpress 1 Wordpress 2025-04-03 5.0 MEDIUM N/A
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463. The menu-header.php vector is already covered by CVE-2005-2110. Other vectors might be covered by CVE-2005-1688. NOTE: if the typical installation of WordPress does not list any site-specific files to wp-includes, then vector [13] is not an exposure.
CVE-2005-3765 1 Exponent 1 Exponent 2025-04-03 7.5 HIGH N/A
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.
CVE-2001-0453 1 Brs 1 Webweaver 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.
CVE-2001-1513 1 Macromedia 1 Jrun 2025-04-03 7.5 HIGH N/A
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.
CVE-2005-2851 1 Smb4k 1 Smb4k 2025-04-03 2.1 LOW N/A
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
CVE-2002-0991 1 Hp 1 Cifs-9000 Server 2025-04-03 7.2 HIGH N/A
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.
CVE-2001-0192 1 Davide Libenzi 1 Xmail 2025-04-03 10.0 HIGH N/A
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.
CVE-2001-1083 1 Icecast 1 Icecast 2025-04-03 5.0 MEDIUM N/A
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).
CVE-2005-3980 1 Edgewall Software 1 Trac 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.