Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29519 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4806 1 Enlightenment 1 Imlib2 2025-04-09 5.1 MEDIUM N/A
Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF (loader_tiff.c) images.
CVE-2007-3961 1 Fsp 1 C Library 2025-04-09 5.0 MEDIUM N/A
Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added.
CVE-2006-6514 1 Flippet.org 1 Winamp Web Interface 2025-04-09 3.5 LOW N/A
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.
CVE-2007-2249 1 Phorum 1 Phorum 2025-04-09 6.5 MEDIUM N/A
include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.
CVE-2007-4944 1 Opera 1 Opera Browser 2025-04-09 5.0 MEDIUM N/A
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.
CVE-2006-6920 1 Nucleus Cms 1 Nucleus Cms 2025-04-09 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php.
CVE-2008-0708 1 Hp 3 442084-b21, 442085-b21, Proliant 2025-04-09 4.6 MEDIUM N/A
HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection.
CVE-2007-0377 1 Xoops 1 Xoops 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors.
CVE-2006-5210 1 Ciphertrust 1 Ironmail 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded "../" sequences ("%252e%252e/").
CVE-2007-1911 1 Microsoft 1 Word 2025-04-09 7.1 HIGH N/A
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
CVE-2009-0618 1 Cisco 1 Application Networking Manager 2025-04-09 8.5 HIGH N/A
Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files.
CVE-2007-0855 1 Rarlab 1 Unrar 2025-04-09 6.8 MEDIUM N/A
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
CVE-2006-6784 1 Netbula 1 Anyboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Netbula Anyboard allows remote attackers to execute arbitrary SQL commands via the user name in the login form.
CVE-2007-2468 1 Hp 1 Openvms 2025-04-09 4.9 MEDIUM N/A
Unspecified vulnerability in HP OpenVMS for Integrity Servers 8.2-1 and 8.3 allows local users to cause a denial of service (crash) via "Program actions relating to exceptions."
CVE-2007-4489 1 Ecentrex 1 Voip Client Module 2025-04-09 6.8 MEDIUM N/A
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method.
CVE-2009-1808 1 Microsoft 1 Windows Xp 2025-04-09 4.9 MEDIUM N/A
Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call.
CVE-2007-0624 1 Maxdev 1 Mdpro 2025-04-09 5.0 MEDIUM N/A
user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.
CVE-2007-2471 1 Sendcard 1 Sendcard 2025-04-09 5.0 MEDIUM N/A
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter.
CVE-2006-5150 1 Openbiblio 1 Openbiblio 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-0068 1 Ibm 1 Lotus Domino 2025-04-09 9.3 HIGH N/A
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.