Total
29619 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2006-1681 | 1 Cherokee | 1 Cherokee Httpd | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. | ||||
CVE-2006-3983 | 1 Ekilat Llc | 1 Php\(reactor\) | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter. | ||||
CVE-2006-4011 | 1 Kayako | 1 Esupport | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter. | ||||
CVE-2002-1425 | 1 John G. Myers | 1 Mpack | 2025-04-03 | N/A |
Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted. | ||||
CVE-2002-1457 | 1 Leszek Krupinski | 1 L-forum | 2025-04-03 | N/A |
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter. | ||||
CVE-2002-1512 | 1 Tolis Group | 1 Bru | 2025-04-03 | N/A |
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file. | ||||
CVE-2002-1513 | 1 Compaq | 1 Tcp-ip Services | 2025-04-03 | N/A |
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges. | ||||
CVE-2003-0807 | 1 Microsoft | 4 Windows 2000, Windows 2003 Server, Windows Nt and 1 more | 2025-04-03 | N/A |
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. | ||||
CVE-2004-0341 | 1 Texas Imperial Software | 1 Wftpd | 2025-04-03 | N/A |
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline. | ||||
CVE-2005-2208 | 1 Privashare | 1 Privashare | 2025-04-03 | N/A |
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message. | ||||
CVE-2006-1891 | 1 Betaboard | 1 Betaboard | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user's profile, possibly using the FormVal_profile parameter. NOTE: it is not clear whether this is a distributable product or a site-specific vulnerability. If it is site-specific, then it should not be included in CVE. | ||||
CVE-2006-2612 | 1 Novell | 1 Client | 2025-04-03 | N/A |
Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prompt. | ||||
CVE-2006-2962 | 1 Oxfam Australia | 1 Emergencies Personnel Information System | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter. | ||||
CVE-2006-4532 | 1 Bernard Pacques | 1 Yet Another Community System Cms | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter. | ||||
CVE-2006-4559 | 1 Bernard Pacques | 1 Yet Another Community System Cms | 2025-04-03 | N/A |
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3) categories/populate.php, (4) comments/populate.php, (5) files/file.php, (6) sections/section.php, (7) sections/populate.php, (8) tables/populate.php, (9) users/user.php, and (10) users/populate.php. The articles/article.php vector is covered by CVE-2006-4532. | ||||
CVE-2001-0198 | 1 Apple | 1 Quicktime | 2025-04-03 | N/A |
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag. | ||||
CVE-2001-0590 | 1 Apache | 1 Tomcat | 2025-04-03 | N/A |
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0). | ||||
CVE-2002-0467 | 2 Ecartis, Listar | 2 Ecartis, Listar | 2025-04-03 | N/A |
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c. | ||||
CVE-2002-0470 | 1 Phpnettoolpack | 1 Phpnettoolpack | 2025-04-03 | N/A |
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path. | ||||
CVE-2002-0474 | 1 Zeroforum | 1 Zeroforum | 2025-04-03 | N/A |
Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag. |