Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2000-1118 1 24link 1 24link 2025-04-03 N/A
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.
CVE-1999-0904 1 Byte Fusion 1 Bftelnet 2025-04-03 N/A
Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.
CVE-1999-0905 1 Axent 1 Raptor Firewall 2025-04-03 N/A
Denial of service in Axent Raptor firewall via malformed zero-length IP options.
CVE-2005-0729 1 Techland 1 Xpand Rally 2025-04-03 N/A
Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message.
CVE-1999-0906 1 Suse 1 Suse Linux 2025-04-03 N/A
Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
CVE-2002-0494 1 Websight Directory System 1 Websight Directory System 2025-04-03 N/A
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name.
CVE-2005-4645 1 3cfr 1 3cfr 2025-04-03 N/A
SQL injection vulnerability in index.php in 3CFR allows remote attackers to execute arbitrary SQL commands via the LangueID parameter.
CVE-2000-1125 1 Redhat 1 Linux 2025-04-03 N/A
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
CVE-1999-0907 1 Steven J. Merrifield 1 Soundcard Cw 2025-04-03 N/A
sccw allows local users to read arbitrary files.
CVE-2002-0496 1 Southwest 1 Southwest 2025-04-03 N/A
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
CVE-1999-0908 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
CVE-1999-0912 1 Freebsd 1 Freebsd 2025-04-03 N/A
FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
CVE-2002-0497 1 Mtr 1 Mtr 2025-04-03 N/A
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.
CVE-1999-0915 1 Pacific Software 1 Url Live 2025-04-03 N/A
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-1128 1 Mcafee 1 Virusscan 2025-04-03 N/A
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.
CVE-2002-1833 1 Xerox 2 Docutech 6110, Docutech 6115 2025-04-03 N/A
The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.
CVE-2002-1834 1 Xerox 2 Docutech 6110, Docutech 6115 2025-04-03 N/A
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.
CVE-2002-1837 1 Ids 1 Ids 2025-04-03 N/A
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.
CVE-2005-2858 1 Rediff 1 Bol 2025-04-03 N/A
The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.
CVE-1999-0965 1 X.org 1 X11 2025-04-03 N/A
Race condition in xterm allows local users to modify arbitrary files via the logging option.