Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29548 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0178 4 Caldera, Conectiva, Mandrakesoft and 1 more 5 Openlinux Edesktop, Linux, Mandrake Linux and 2 more 2025-04-03 2.1 LOW N/A
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
CVE-2002-1865 2 D-link, Linksys 4 Di-804, Dl-704, Befw11s4 and 1 more 2025-04-03 5.0 MEDIUM N/A
Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.
CVE-2005-1490 2 Icewarp, Merak 2 Web Mail, Mail Server 2025-04-03 2.1 LOW N/A
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.
CVE-1999-1189 1 Netscape 2 Communicator, Navigator 2025-04-03 7.5 HIGH N/A
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
CVE-2005-2170 1 Ibm 1 Tivoli Management Framework 2025-04-03 5.0 MEDIUM N/A
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
CVE-1999-0447 1 Hp 1 Mpe Ix 2025-04-03 4.6 MEDIUM N/A
Local users can gain privileges using the debug utility in the MPE/iX operating system.
CVE-2001-0087 1 Michael Glickman 1 Itetris 2025-04-03 7.2 HIGH N/A
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.
CVE-2001-1289 1 Id Software 1 Quake 3 Arena 2025-04-03 5.0 MEDIUM N/A
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.
CVE-2005-4445 1 David Harris 1 Pegasus Mail 2025-04-03 5.1 MEDIUM N/A
Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffer overflow.
CVE-2006-3580 1 Asp Stats Generator 1 Asp Stats Generator 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.
CVE-2005-0013 1 Ncpfs 1 Ncpfs 2025-04-03 7.2 HIGH N/A
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
CVE-2001-0488 1 Hp 1 Hp-ux 2025-04-03 2.1 LOW N/A
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
CVE-2006-3957 1 Bosdev 1 Bosdates 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.
CVE-2000-1209 2 Compaq, Microsoft 4 Insight Manager, Insight Manager Xe, Data Engine and 1 more 2025-04-03 10.0 HIGH N/A
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
CVE-2005-1606 1 Positive Software 1 H-sphere Winbox 2025-04-03 4.6 MEDIUM N/A
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
CVE-2001-1354 1 Netwin 2 Dmail, Surgeftp 2025-04-03 4.6 MEDIUM N/A
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
CVE-2004-0699 1 Checkpoint 2 Firewall-1, Vpn-1 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.
CVE-2005-0090 1 Redhat 2 Enterprise Linux, Enterprise Linux Desktop 2025-04-03 2.1 LOW N/A
A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).
CVE-2006-0850 1 Ilch.de 1 Ilchclan 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-3241 1 Ethereal Group 1 Ethereal 2025-04-03 5.0 MEDIUM N/A
Multiple vulnerabilities in Ethereal 0.10.12 and earlier allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors in the (1) ISAKMP, (2) FC-FCS, (3) RSVP, and (4) ISIS LSP dissector.