Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29539 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0937 1 Unu Networks 1 Mailgust 2025-04-03 5.0 MEDIUM N/A
U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.
CVE-2002-0124 1 Mdg Computer Services 1 Web Server 4d Ecommerce 2025-04-03 5.0 MEDIUM N/A
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
CVE-2004-1279 1 Jpegtoavi 1 Jpegtoavi 2025-04-03 10.0 HIGH N/A
Buffer overflow in the get_file_list_stdin function in jpegtoavi 1.5 allows remote attackers to execute arbitrary code via a crafted set of JPEG files and filenames.
CVE-2006-4737 1 Jetbox 1 Jetbox Cms 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php in Jetbox CMS allows remote attackers to inject arbitrary web script or HTML via the item parameter. NOTE: The view vector is already covered by CVE-2006-3586.2.
CVE-2000-0948 1 Gnome 1 Gnorpm 2025-04-03 7.2 HIGH N/A
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
CVE-2002-2015 1 Postnuke Software Foundation 1 Postnuke 2025-04-03 7.5 HIGH N/A
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.
CVE-2004-1565 1 W-agora 1 W-agora 2025-04-03 5.0 MEDIUM N/A
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
CVE-2000-0619 1 Toplayer 1 Appswitch 2025-04-03 5.0 MEDIUM N/A
Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.
CVE-2006-2255 1 Creative Software 1 Community Portal 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
CVE-2004-2055 1 Phpbb Group 1 Phpbb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.
CVE-2006-1767 1 Nicecoder 1 Indexu 2025-04-03 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6) detail.php, (7) fav.php, (8) get_rated.php, (9) login.php, (10) mailing_list.php, (11) new.php, (12) modify.php, (13) pick.php, (14) power_search.php, (15) rating.php, (16) register.php, (17) review.php, (18) rss.php, (19) search.php, (20) send_pwd.php, (21) sendmail.php, (22) tell_friend.php, (23) top_rated.php, (24) user_detail.php, and (25) user_search.php; and the (26) base_path parameter in invoice.php.
CVE-2001-1044 1 Basilix 1 Basilix Webmail 2025-04-03 7.5 HIGH N/A
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
CVE-2002-1764 1 Adobe 1 Acrobat Reader 2025-04-03 2.1 LOW N/A
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2001-1457 1 Nobreak Technologies 1 Crazywwwboard 2025-04-03 7.5 HIGH N/A
Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.
CVE-1999-0336 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in mstm in HP-UX allows local users to gain root access.
CVE-1999-0155 1 Aladdin Enterprises 1 Ghostscript 2025-04-03 7.5 HIGH N/A
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
CVE-2001-0327 1 Iplanet 1 Iplanet Web Server 2025-04-03 5.0 MEDIUM N/A
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
CVE-2004-0824 1 Apple 1 Mac Os X 2025-04-03 2.1 LOW N/A
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
CVE-2004-1633 1 Mozilla 1 Bugzilla 2025-04-03 5.0 MEDIUM N/A
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.
CVE-2001-1163 1 Munica 1 Netsql 2025-04-03 10.0 HIGH N/A
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.