Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2002-0487 1 Workforceroi 1 Xpede 2025-04-03 N/A
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.
CVE-1999-0896 1 Realnetworks 1 Realserver G2 2025-04-03 N/A
Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.
CVE-2002-0488 1 Linux Directory Penguin 1 Linux Directory Penguin Traceroute 2025-04-03 N/A
Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.
CVE-2002-0492 1 Dcscripts 1 Dcshop 2025-04-03 N/A
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
CVE-2005-0700 1 Aztek Forum 1 Aztek Forum 2025-04-03 N/A
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.
CVE-1999-0902 1 Linux-nis 1 Ypserv 2025-04-03 N/A
ypserv allows local administrators to modify password tables.
CVE-1999-0903 1 Ibm 1 Aix 2025-04-03 N/A
genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.
CVE-2000-1118 1 24link 1 24link 2025-04-03 N/A
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.
CVE-2005-0986 1 Ibm 1 Lotus Domino Server 2025-04-03 N/A
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
CVE-1999-0983 1 Internic 1 Whois Lookup 2025-04-03 N/A
Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
CVE-1999-0984 1 Matts Whois 1 Matts Whois 2025-04-03 N/A
Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
CVE-2002-1851 1 Ipswitch 1 Ws Ftp Pro 2025-04-03 N/A
Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.
CVE-2002-1883 1 Trolltech 1 Qt Assistant 2025-04-03 N/A
Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service.
CVE-1999-0997 3 Millenux Gmbh, Redhat, University Of Washington 3 Anonftp, Linux, Wu-ftpd 2025-04-03 N/A
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
CVE-1999-1001 1 Cisco 1 Cache Engine 2025-04-03 N/A
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
CVE-2000-1136 1 Debian 1 Elvis Tiny 2025-04-03 N/A
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.
CVE-2002-1893 1 Argosoft 1 Argosoft Mail Server 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.
CVE-1999-1002 1 Netscape 1 Communicator 2025-04-03 N/A
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
CVE-2006-4046 1 Open Cubic Player 1 Open Cubic Player 2025-04-03 N/A
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.
CVE-1999-1003 1 Jgaa 1 Warftpd 2025-04-03 N/A
War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.