Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29539 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1362 1 Matthew Smith 1 Micq 2025-04-03 5.0 MEDIUM N/A
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
CVE-2001-1087 1 Network Appliance 1 Netcache 2025-04-03 7.5 HIGH N/A
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.
CVE-2003-0865 1 Mpg123 1 Mpg123 2025-04-03 7.5 HIGH N/A
Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.
CVE-2005-2849 1 Barracuda Networks 1 Barracuda Spam Firewall 2025-04-03 6.4 MEDIUM N/A
Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin directory via the -w argument to Tcpdump.
CVE-2004-1540 1 Zyxel 2 Prestige, Zynos 2025-04-03 5.0 MEDIUM N/A
ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
CVE-1999-1289 1 Mirabilis 1 Icq 2025-04-03 7.5 HIGH N/A
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.
CVE-2000-1180 1 Oracle 1 Oracle8i 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.
CVE-2006-1673 1 Jelsoft 1 Vbug Tracker 2025-04-03 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.
CVE-2002-0196 1 Acd Incorporated 1 Cwpapi 2025-04-03 6.4 MEDIUM N/A
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.
CVE-2000-0869 2 Apache, Suse 2 Http Server, Suse Linux 2025-04-03 5.0 MEDIUM N/A
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
CVE-2006-1625 1 Mybulletinboard 1 Mybulletinboard 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode email tag, as demonstrated using the onmousemove event.
CVE-2006-2143 1 Jcink 1 Textfilebb 2025-04-03 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.
CVE-2003-0605 1 Microsoft 1 Windows 2000 2025-04-03 7.5 HIGH N/A
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.
CVE-2005-2372 1 Oracle 1 Forms 2025-04-03 7.2 HIGH N/A
Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.
CVE-2002-2013 2 Mozilla, Netscape 3 Mozilla, Communicator, Navigator 2025-04-03 5.0 MEDIUM N/A
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
CVE-2000-0069 1 Sun 1 Solstice Backup 2025-04-03 2.1 LOW N/A
The recover program in Solstice Backup allows local users to restore sensitive files.
CVE-2006-2212 1 Karjasoft 1 Sami Ftp Server 2025-04-03 6.4 MEDIUM N/A
Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.
CVE-2006-0958 1 Zoneo-soft 1 Freeforum 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.
CVE-1999-1512 1 Amavis 1 Virus Scanner 2025-04-03 10.0 HIGH N/A
The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.
CVE-2001-0733 1 Ralf S. Engelschall 1 Eperl 2025-04-03 7.5 HIGH N/A
The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.