Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2006-4072 1 Club-nuke 1 Club-nuke 2025-04-03 N/A
Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via the (2) menu_id parameter to menu.asp.
CVE-2000-0693 1 Tech-source 1 Raptor Gfx Pgx32 2025-04-03 N/A
pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.
CVE-2000-0695 1 Tech-source 1 Raptor Gfx Pgx32 2025-04-03 N/A
Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.
CVE-2002-0870 1 Cisco 2 Content Services Switch 11000, Webns 2025-04-03 N/A
The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.
CVE-2002-2109 1 Matt Wright 1 Formmail 2025-04-03 N/A
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
CVE-1999-1226 1 Netscape 1 Communicator 2025-04-03 N/A
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.
CVE-2004-1413 1 Kayako 1 Esupport 2025-04-03 N/A
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.
CVE-2000-0696 1 Sun 1 Solaris Answerbook2 2025-04-03 N/A
The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.
CVE-1999-0378 1 Trend Micro 1 Interscan Viruswall 2025-04-03 N/A
InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.
CVE-1999-0418 2025-04-03 N/A
Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.
CVE-1999-1255 1 Ccs Network 1 Hyperseek Search Engine 2025-04-03 N/A
Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.
CVE-2000-0699 1 Hp 1 Hp-ux 2025-04-03 N/A
Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.
CVE-2002-0872 1 L2tpd 1 L2tpd 2025-04-03 N/A
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
CVE-1999-0972 1 Wolfpack Development 1 Xshipwars 2025-04-03 N/A
Buffer overflow in Xshipwars xsw program.
CVE-2001-0101 1 Fetchmail 1 Fetchmail 2025-04-03 N/A
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.
CVE-1999-0975 1 Microsoft 3 Windows 95, Windows 98, Windows Nt 2025-04-03 N/A
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
CVE-1999-0976 1 Eric Allman 1 Sendmail 2025-04-03 N/A
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
CVE-1999-0978 1 Debian 1 Debian Linux 2025-04-03 N/A
htdig allows remote attackers to execute commands via filenames with shell metacharacters.
CVE-2000-0743 1 University Of Minnesota 1 Gopherd 2025-04-03 N/A
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.
CVE-2001-0110 1 Iomega 1 Jazip 2025-04-03 N/A
Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.