Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-1999-0744 1 Netscape 2 Enterprise Server, Fasttrack Server 2025-04-03 N/A
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
CVE-2000-0483 2 Redhat, Zope 2 Linux Powertools, Zope 2025-04-03 N/A
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
CVE-2002-2047 1 Sketch 1 Sketch 2025-04-03 N/A
The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.
CVE-2001-0025 1 Leif M. Wright 1 Ad.cgi 2025-04-03 N/A
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
CVE-2006-3718 1 Oracle 1 Exchange 2025-04-03 N/A
Multiple unspecified vulnerabilities in Oracle Exchange for Oracle E-Business Suite and Applications 6.2.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS16 and (2) APPS17.
CVE-2000-0568 1 Sybergen 1 Secure Desktop 2025-04-03 N/A
Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.
CVE-2002-2057 1 Teekai 1 Teekai Forum 2025-04-03 N/A
TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
CVE-2003-0615 4 Cgi.pm, Debian, Openpkg and 1 more 5 Cgi.pm, Debian Linux, Openpkg and 2 more 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
CVE-1999-0204 1 Eric Allman 1 Sendmail 2025-04-03 N/A
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
CVE-1999-0217 1 Sun 1 Sunos 2025-04-03 N/A
Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.
CVE-2000-0592 1 Sapporoworks 1 Sapporoworks Winproxy 2025-04-03 N/A
Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.
CVE-1999-0852 1 Ibm 1 Websphere Application Server 2025-04-03 N/A
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
CVE-2001-0031 1 Broadvision 1 One-to-one Enterprise Server 2025-04-03 N/A
BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.
CVE-2005-2765 1 Microsoft 2 Windows 2003 Server, Windows Xp 2025-04-03 N/A
The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions. NOTE: the vendor disputes this issue, saying that since administrative privileges are already required, it is not a vulnerability. CVE has not yet formally decided if such "information hiding" issues should be included.
CVE-2000-0595 1 Freebsd 1 Freebsd 2025-04-03 N/A
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
CVE-1999-0973 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
CVE-2000-0605 1 Blackboard 1 Courseinfo 2025-04-03 N/A
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.
CVE-2002-2061 2 Mozilla, Netscape 2 Mozilla, Navigator 2025-04-03 N/A
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
CVE-2003-0617 1 Hugo Rabson 1 Mindi 2025-04-03 N/A
mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
CVE-1999-0295 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.