Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29539 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1113 1 Sqlgrey 1 Sqlgrey Postfix Greylisting Service 2025-04-03 10.0 HIGH N/A
SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.
CVE-2006-3292 1 Jaws 1 Jaws 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).
CVE-2005-2320 1 Webcalendar 1 Webcalendar 2025-04-03 7.5 HIGH N/A
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
CVE-2005-0704 1 Ethereal Group 1 Ethereal 2025-04-03 7.5 HIGH N/A
Buffer overflow in the Etheric dissector in Ethereal 0.10.7 through 0.10.9 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.
CVE-2000-0651 1 Novell 1 Bordermanager 2025-04-03 7.5 HIGH N/A
The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.
CVE-2002-2108 1 Sony 1 Vaio Manual Cybersupport 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.
CVE-2004-1605 2 Best Software, Saleslogix Corporation 2 Saleslogix, Saleslogix 2025-04-03 7.5 HIGH N/A
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
CVE-2003-1308 1 Fvwm 1 Fvwm 2025-04-03 4.6 MEDIUM N/A
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
CVE-2006-1046 1 Monopd 1 Monopd 2025-04-03 5.0 MEDIUM N/A
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.
CVE-2005-3100 1 Astaro 1 Security Linux 2025-04-03 5.0 MEDIUM N/A
Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.
CVE-2006-2147 1 Resmgr 1 Resmgrd 2025-04-03 3.6 LOW N/A
resmgrd in resmgr for SUSE Linux and other distributions does not properly handle when access to a USB device is granted by using "usb:<bus>,<dev>" notation, which grants access to all USB devices and allows local users to bypass intended restrictions. NOTE: this is a different vulnerability than CVE-2005-4788.
CVE-2002-0459 1 Linux-sottises 2 Board-tnk, News-tnk 2025-04-03 7.6 HIGH N/A
Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.
CVE-2006-4492 1 Cybozu 1 Cybozu Office 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in Cybozu Office 6.5 Build 1.2 for Windows allows remote attackers to obtain sensitive information, including users and groups, via unspecified vectors.
CVE-2005-4174 1 Efiction Project 1 Efiction 2025-04-03 7.5 HIGH N/A
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.
CVE-1999-0487 1 Microsoft 1 Internet Explorer 2025-04-03 2.6 LOW N/A
The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
CVE-2006-0477 1 Git 1 Git 2025-04-03 7.5 HIGH N/A
Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link.
CVE-2006-0643 1 Wiredred 1 E Pop Web Conferencing 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference.
CVE-2004-1623 1 Microsoft 1 Windows Xp 2025-04-03 5.0 MEDIUM N/A
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.
CVE-2006-1082 1 Phparcadescript 1 Phparcadescript 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4) cell_title_background_color and (5) browse_cat_name parameters in browse.php, the (6) gamefile parameter in displaygame.php, and (7) possibly other parameters in unspecified PHP scripts.
CVE-2005-1420 1 Raysoft 1 Video Cam Server 2025-04-03 5.0 MEDIUM N/A
Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).