Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2000-0973 1 Daniel Stenberg 1 Curl 2025-04-03 N/A
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.
CVE-2006-3988 1 Knusperleicht 1 Newsreporter 2025-04-03 N/A
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.
CVE-2000-0856 1 Xs4all Data 1 Xs4all Data Sunftp 2025-04-03 N/A
Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.
CVE-2000-0862 1 Allaire 1 Spectra 2025-04-03 N/A
Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.
CVE-2006-3239 1 Vbzoom 1 Vbzoom 2025-04-03 N/A
SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter.
CVE-2006-3250 1 Microsoft 1 Windows Live Messenger 2025-04-03 N/A
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is imported by the user.
CVE-2006-4439 1 Sun 1 Solaris 2025-04-03 N/A
pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
CVE-2006-3271 1 Softbiz 1 Dating Script 2025-04-03 N/A
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d) index.php, and (e) news_desc.php.
CVE-1999-0112 2 Cde, Ibm 2 Cde, Aix 2025-04-03 N/A
Buffer overflow in AIX dtterm program for the CDE.
CVE-1999-0789 1 Ibm 1 Aix 2025-04-03 N/A
Buffer overflow in AIX ftpd in the libc library.
CVE-1999-0803 1 Ibm 1 Aix Enetwork Firewall 2025-04-03 N/A
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
CVE-2000-0873 1 Ibm 1 Aix 2025-04-03 N/A
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.
CVE-2002-0231 1 Khaled Mardam-bey 1 Mirc 2025-04-03 N/A
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.
CVE-2002-0283 1 Microsoft 1 Windows Xp 2025-04-03 N/A
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.
CVE-2000-0487 1 Microsoft 1 Windows 2000 2025-04-03 N/A
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.
CVE-2006-3507 1 Apple 2 Mac Os X, Mac Os X Server 2025-04-03 N/A
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.
CVE-2000-0673 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 N/A
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
CVE-2006-3525 1 Phpcredo 1 Phcdownload 2025-04-03 N/A
SQL injection vulnerability in category.php in PHCDownload 1.0.0 Final and 1.0.0 Release Candidate 6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2000-0860 1 Php 1 Php 2025-04-03 N/A
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.
CVE-2006-4437 1 Venture Nine 1 Tagger Le 2025-04-03 N/A
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.