Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29545 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0780 1 Novell 1 Bordermanager 2025-04-03 5.0 MEDIUM N/A
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.
CVE-2006-3156 1 Thinkfactory 1 Ultimate Eshop 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate eShop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the subid parameter.
CVE-1999-0045 2 Apache, Netscape 4 Http Server, Commerce Server, Communications Server and 1 more 2025-04-03 7.5 HIGH N/A
List of arbitrary files on Web host via nph-test-cgi script.
CVE-2005-1998 1 Mcgallery 1 Mcgallery 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
CVE-1999-0342 1 Pam 1 Pam 2025-04-03 6.2 MEDIUM N/A
Linux PAM modules allow local users to gain root access using temporary files.
CVE-2001-0684 1 Netscape 1 Collabra Server 2025-04-03 5.0 MEDIUM N/A
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.
CVE-2004-2239 1 Inter7 1 Vpopmail \(vchkpw\) 2025-04-03 7.5 HIGH N/A
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
CVE-2002-1477 1 The Cacti Group 1 Cacti 2025-04-03 7.5 HIGH N/A
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
CVE-2002-0956 1 Iss 1 Blackice Agent 2025-04-03 7.5 HIGH N/A
BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions.
CVE-2006-0426 1 Bea 1 Weblogic Server 2025-04-03 7.5 HIGH N/A
BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.
CVE-1999-1049 1 Broadcom 1 Arcserve Backup 2025-04-03 10.0 HIGH N/A
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
CVE-2005-2790 1 Bfcommand And Control Software 2 Bfcc, Bfvcc 2025-04-03 7.5 HIGH N/A
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.
CVE-2005-3507 1 Cutephp 1 Cutenews 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
CVE-2006-3392 2 Usermin, Webmin 2 Usermin, Webmin 2025-04-03 5.0 MEDIUM N/A
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.
CVE-1999-1170 2 Ipswitch, Progress 2 Imail, Ws Ftp Server 2025-04-03 4.6 MEDIUM N/A
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
CVE-2005-4319 1 Limbo Cms 1 Limbo Cms 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." sequences in the option parameter.
CVE-2006-3880 1 Microsoft 3 Windows 2000, Windows 2003 Server, Windows Xp 2025-04-03 5.0 MEDIUM N/A
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation.
CVE-2002-0599 1 Blahz-dns 1 Blahz-dns 2025-04-03 10.0 HIGH N/A
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.
CVE-2001-0044 1 Lexmark 1 Markvision 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.
CVE-2005-4345 1 Macromedia 1 Coldfusion 2025-04-03 7.2 HIGH N/A
Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.