Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29682 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0574 1 Jason Rahaim 1 Mp3mystic 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.
CVE-2006-3835 1 Apache 1 Tomcat 2025-04-03 5.0 MEDIUM N/A
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
CVE-2006-4722 1 Openbb 1 Openbb 2025-04-03 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) index.php and possibly (2) collector.php.
CVE-2005-3715 1 Senao 1 Si-680h Wireless Voip Phone 2025-04-03 7.5 HIGH N/A
Senao SI-680H Wireless VoIP Phone Firmware 0.03.0839 leaves the VxWorks debugger UDP port 17185 available without authentication, which allows attackers to access the phone OS, obtain sensitive information, and cause a denial of service.
CVE-2004-0806 1 Cdrtools 1 Cdrecord 2025-04-03 7.2 HIGH N/A
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
CVE-2006-0715 1 Solucija 1 Snews 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
CVE-2006-0714 1 Flyspray 1 Flyspray 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.
CVE-2004-1898 1 Tildeslash 1 Monit 2025-04-03 10.0 HIGH N/A
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
CVE-2000-0977 1 Oatmeal Studios 1 Mail File 2025-04-03 5.0 MEDIUM N/A
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
CVE-2004-0353 1 Gnu 1 Anubis 2025-04-03 10.0 HIGH N/A
Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.
CVE-2001-1545 1 Macromedia 1 Jrun 2025-04-03 5.0 MEDIUM N/A
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
CVE-2005-4666 1 Phlymail 1 Phlymail 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.
CVE-2002-0789 1 Mnogosearch 1 Mnogosearch 2025-04-03 7.5 HIGH N/A
Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter.
CVE-2004-1167 1 Gentoo 1 Mirrorselect 2025-04-03 5.0 MEDIUM N/A
mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.
CVE-2005-1057 1 Cisco 1 Ios 2025-04-03 7.5 HIGH N/A
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
CVE-1999-0724 1 Openbsd 1 Openbsd 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
CVE-2005-3369 1 Woltlab 1 Burning Board 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.
CVE-1999-0021 1 Muhammad A. Muquit 1 Wwwcount 2025-04-03 7.5 HIGH N/A
Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.
CVE-2006-2993 1 My Photo Scrapbook 1 My Photo Scrapbook 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.
CVE-2005-2925 1 Sgi 1 Irix 2025-04-03 7.2 HIGH N/A
runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.