Total
29550 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-4413 | 1 Ibm | 1 Websphere Application Server | 2025-04-03 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie Reviewer, and (6) Movie Review fields to (d) TechnologySamples/MovieReview2_1. | |||||
CVE-1999-0120 | 1 Sun | 1 Sunos | 2025-04-03 | 7.2 HIGH | N/A |
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root. | |||||
CVE-2000-0074 | 1 Powerscripts | 1 Plusmail | 2025-04-03 | 7.5 HIGH | N/A |
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | |||||
CVE-2004-0334 | 1 Innomedia | 1 Innomedia Videophone | 2025-04-03 | 5.0 MEDIUM | N/A |
InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error. | |||||
CVE-2002-1482 | 1 Phpgb | 1 Phpgb | 2025-04-03 | 10.0 HIGH | N/A |
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry. | |||||
CVE-2005-3351 | 1 Apache | 1 Spamassassin | 2025-04-03 | 5.0 MEDIUM | N/A |
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl. | |||||
CVE-2006-3504 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2025-04-03 | 5.1 MEDIUM | N/A |
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari. | |||||
CVE-2005-2632 | 1 Mediabox404 | 1 Mediabox404 | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in login_admin_mediabox404.php in mediabox404 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the User field. | |||||
CVE-2005-1045 | 1 Centrinity | 1 Centrinity Firstclass Desktop Client | 2025-04-03 | 7.5 HIGH | N/A |
OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. | |||||
CVE-1999-0306 | 1 Hp | 1 Vvos | 2025-04-03 | 7.2 HIGH | N/A |
buffer overflow in HP xlock program. | |||||
CVE-2004-1580 | 1 Devellion | 1 Cubecart | 2025-04-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |||||
CVE-2003-1198 | 1 Cherokee | 1 Cherokee Httpd | 2025-04-03 | 5.0 MEDIUM | N/A |
connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field. | |||||
CVE-2006-2915 | 1 Deluxebb | 1 Deluxebb | 2025-04-03 | 5.1 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration. | |||||
CVE-2005-4595 | 1 Gentoo | 2 Nview, Xnview | 2025-04-03 | 7.2 HIGH | N/A |
Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory. | |||||
CVE-2005-3448 | 1 Oracle | 1 Application Server | 2025-04-03 | 10.0 HIGH | N/A |
Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01. | |||||
CVE-2006-2253 | 1 Otterware | 1 Statit | 2025-04-03 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter. | |||||
CVE-2006-1498 | 1 Mediawiki | 1 Mediawiki | 2025-04-03 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links. | |||||
CVE-2006-3676 | 1 Planet Concept | 1 Planetgallery | 2025-04-03 | 5.1 MEDIUM | N/A |
admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. | |||||
CVE-1999-0686 | 2 Hp, Netscape | 2 Hp-ux, Enterprise Server | 2025-04-03 | 5.0 MEDIUM | N/A |
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL. | |||||
CVE-2004-1470 | 1 Snipsnap | 1 Snipsnap | 2025-04-03 | 5.0 MEDIUM | N/A |
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server. |