Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29549 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0118 1 Infopop 1 Ultimate Bulletin Board 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.
CVE-2000-0865 1 Tridia 1 Doublevision 2025-04-03 7.2 HIGH N/A
Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.
CVE-2001-1257 1 Horde 1 Imp 2025-04-03 7.5 HIGH N/A
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.
CVE-2005-1060 1 Novell 1 Netware 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.
CVE-2002-0757 2 Usermin, Webmin 2 Usermin, Webmin 2025-04-03 7.5 HIGH N/A
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.
CVE-2005-1359 1 Text.cgi 1 Text.cgi 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
CVE-2006-2899 1 Estsoft 1 Internetdisk 2025-04-03 6.5 MEDIUM N/A
Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory.
CVE-2004-1348 1 Sun 2 Solaris, Sunos 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).
CVE-2006-0835 1 Mitridat 1 Web Calendar Pro 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter.
CVE-2006-1817 1 The War Forge 1 Warforge.news 2025-04-03 2.6 LOW N/A
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.
CVE-2006-2489 1 Nagios 1 Nagios 2025-04-03 7.5 HIGH N/A
Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a content length (Content-Length) HTTP header. NOTE: this is a different vulnerability than CVE-2006-2162.
CVE-2005-0505 1 Stackworks Enterprises 1 Information Resource Manager 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.
CVE-2006-2965 1 Particle Soft 1 Particle Whois 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."
CVE-2005-0545 1 Microsoft 2 Windows 2000, Windows Xp 2025-04-03 7.2 HIGH N/A
Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
CVE-2006-1698 1 Matt Wright 1 Matt Wright Guestbook 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, although it is likely that they are the result of post-disclosure analysis.
CVE-1999-0711 1 Oracle 1 Oracle8i 2025-04-03 4.6 MEDIUM N/A
The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.
CVE-2002-0119 1 Alcatel 1 Speed Touch Home 2025-04-03 5.0 MEDIUM N/A
Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection.
CVE-2004-0380 1 Microsoft 1 Outlook Express 2025-04-03 10.0 HIGH N/A
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
CVE-2000-0430 1 Mcmurtrey Whitaker And Associates 1 Cart32 2025-04-03 5.0 MEDIUM N/A
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
CVE-2006-0578 1 Bluecoat 1 Sgos 2025-04-03 7.5 HIGH N/A
Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.