Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0584 2 Debian, Freebsd 2 Debian Linux, Freebsd 2025-04-03 10.0 HIGH N/A
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
CVE-2002-0719 1 Microsoft 1 Content Management Server 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
CVE-2002-0965 1 Oracle 1 Oracle9i 2025-04-03 7.5 HIGH N/A
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.
CVE-2005-2241 1 Cisco 1 Call Manager 2025-04-03 5.0 MEDIUM N/A
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.
CVE-2002-1364 1 Ehud Gavron 1 Tracesroute 2025-04-03 7.2 HIGH N/A
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.
CVE-2003-0054 1 Apple 2 Darwin Streaming Server, Quicktime Streaming Server 2025-04-03 7.5 HIGH N/A
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
CVE-2001-0358 2 Sierra, Valve Software 2 Half-life, Half-life 2025-04-03 7.5 HIGH N/A
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.
CVE-2006-1742 1 Mozilla 4 Firefox, Mozilla Suite, Seamonkey and 1 more 2025-04-03 5.0 MEDIUM N/A
The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.
CVE-2006-0630 1 Ritlabs 1 The Bat 2025-04-03 5.0 MEDIUM N/A
RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.
CVE-2006-1433 1 Annuaire 1 Directory 2025-04-03 5.0 MEDIUM N/A
Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.
CVE-2006-0415 1 Sleeperchat 1 Sleeperchat 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.
CVE-2000-0233 1 Suse 1 Suse Linux Imap Server 2025-04-03 10.0 HIGH N/A
SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.
CVE-2006-0193 1 Positive Software 1 H-sphere 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.
CVE-2006-4876 1 Jupiter Cms 1 Jupiter Cms 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.
CVE-2005-3370 1 Arcavir 1 Arcavir 2005 2025-04-03 5.1 MEDIUM N/A
Multiple interpretation error in ArcaVir 2005 package 2005-06-21 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
CVE-2005-2827 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 7.2 HIGH N/A
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."
CVE-2004-2308 1 Cpanel 1 Cpanel 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the dir parameter in dohtaccess.html.
CVE-2005-3393 1 Openvpn 2 Openvpn, Openvpn Access Server 2025-04-03 7.5 HIGH N/A
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
CVE-2002-1452 1 Mywebserver 1 Mywebserver 2025-04-03 7.5 HIGH N/A
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.
CVE-2004-1722 1 Merak 1 Mail Server 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.