Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29539 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-1133 1 Flicks Software 1 Authentix 2025-04-03 5.0 MEDIUM N/A
Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.
CVE-2001-1198 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
CVE-1999-0313 1 Sgi 1 Irix 2025-04-03 7.2 HIGH N/A
disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
CVE-2005-0961 1 Horde 1 Application Framework 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.
CVE-2004-0595 4 Avaya, Php, Redhat and 1 more 8 Converged Communications Server, Integrated Management, S8300 and 5 more 2025-04-03 6.8 MEDIUM N/A
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
CVE-2004-2068 1 Leafnode 1 Leafnode 2025-04-03 5.0 MEDIUM N/A
fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.
CVE-2006-1713 1 Phpmyforum 1 Phpmyforum 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Christoph Roeder phpMyForum 4.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2005-3127 1 Lucidcms 1 Lucidcms 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
CVE-2005-2228 1 Bdc Enterprises 1 Web Wiz Forums 2025-04-03 5.0 MEDIUM N/A
Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.
CVE-2004-1322 1 Cisco 1 Unity Server 2025-04-03 7.5 HIGH N/A
Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
CVE-2002-1013 1 Inktomi 3 Media-ixt, Traffic Edge, Traffic Server 2025-04-03 7.2 HIGH N/A
Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argument.
CVE-2000-0095 1 Hp 1 Hp-ux 2025-04-03 5.0 MEDIUM N/A
The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.
CVE-2005-0574 1 Cupidsystems 1 Cis Webserver 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.
CVE-2005-1093 1 Popup Plus Plugin 1 Popup Plus Plugin For Miranda Im 2025-04-03 7.5 HIGH N/A
Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.
CVE-1999-1460 1 Bmc 1 Patrol Agent 2025-04-03 7.2 HIGH N/A
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.
CVE-2000-0698 1 Minicom 1 Minicom 2025-04-03 5.0 MEDIUM N/A
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.
CVE-2004-2432 1 Winagents 1 Tftp Server 2025-04-03 5.0 MEDIUM N/A
WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.
CVE-2006-1820 1 Modxcms 1 Modxcms 2025-04-03 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.
CVE-2005-3960 1 Kadu 1 Kadu 2025-04-03 7.8 HIGH N/A
Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information.
CVE-2000-0381 1 Gossamer Threads 1 Dbman 2025-04-03 6.4 MEDIUM N/A
The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.