Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29682 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1399 1 Opentools 1 Attachment Mod 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.
CVE-1999-1340 1 Hylafax 1 Hylafax 2025-04-03 7.2 HIGH N/A
Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.
CVE-2002-1038 1 Michael Dean 1 Double Choco Latte 2025-04-03 5.0 MEDIUM N/A
Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.
CVE-2005-2207 1 Elemental Software 1 Cartwiz 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVE-2006-1465 1 Apple 1 Quicktime 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.
CVE-1999-0256 2 Jgaa, Microsoft 3 Warftpd, Windows 95, Windows Nt 2025-04-03 7.5 HIGH N/A
Buffer overflow in War FTP allows remote execution of commands.
CVE-2005-0633 1 Cerulean Studios 2 Trillian, Trillian Pro 2025-04-03 7.5 HIGH N/A
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.
CVE-2004-2255 1 Phpmyfaq 1 Phpmyfaq 2025-04-03 6.4 MEDIUM N/A
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.
CVE-2000-0227 1 Linux 1 Linux Kernel 2025-04-03 2.1 LOW N/A
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.
CVE-2002-1107 1 Cisco 1 Vpn Client 2025-04-03 7.5 HIGH N/A
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.
CVE-2004-1764 1 Hp 1 Hp-ux 2025-04-03 7.2 HIGH N/A
Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.
CVE-2003-0894 1 Oracle 1 Oracle9i 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.
CVE-2002-1505 1 Woltlab 1 Burning Board 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
CVE-2005-2438 1 Usebb 1 Usebb 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.
CVE-2005-0146 1 Mozilla 2 Firefox, Mozilla 2025-04-03 5.0 MEDIUM N/A
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
CVE-2006-3691 1 Vbzoom 1 Vbzoom 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier allow remote attackers to execute arbitrary SQL commands via the UserID parameter to (1) ignore-pm.php, (2) sendmail.php, (3) reply.php or (4) sub-join.php.
CVE-1999-0613 2025-04-03 N/A N/A
The rpc.sprayd service is running.
CVE-2005-3848 1 Linux 1 Linux Kernel 2025-04-03 7.8 HIGH N/A
Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."
CVE-2006-3884 1 Gonafish 1 Linkscaffe 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in a deadlink action. NOTE: this issue can also be used for path disclosure by a forced SQL error, or to modify PHP files using OUTFILE.
CVE-2004-1103 1 Tips 1 Mailpost 2025-04-03 5.0 MEDIUM N/A
MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.