Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-1999-0973 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
CVE-2000-0605 1 Blackboard 1 Courseinfo 2025-04-03 N/A
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.
CVE-2002-2061 2 Mozilla, Netscape 2 Mozilla, Navigator 2025-04-03 N/A
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
CVE-2003-0617 1 Hugo Rabson 1 Mindi 2025-04-03 N/A
mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
CVE-1999-0295 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
CVE-1999-0864 1 Sco 1 Unixware 2025-04-03 N/A
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
CVE-1999-0285 1 Microsoft 1 Windows Nt 2025-04-03 N/A
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0288 1 Microsoft 1 Windows Nt 2025-04-03 N/A
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
CVE-1999-0865 1 Stalker 1 Communigate Pro 2025-04-03 N/A
Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.
CVE-1999-0866 1 Sco 1 Unixware 2025-04-03 N/A
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
CVE-1999-1006 1 Novell 1 Groupwise 2025-04-03 N/A
Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.
CVE-2004-1384 1 Phpgroupware 1 Phpgroupware 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.
CVE-1999-1025 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
CVE-2004-1780 1 Info Touch 1 Surfnet 2025-04-03 N/A
Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.
CVE-2005-0444 1 Vmware 1 Workstation 2025-04-03 N/A
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
CVE-2005-0831 1 Php-post 1 Php-post Web Forum 2025-04-03 N/A
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
CVE-2005-4814 1 Middlebury College 1 Segue Cms 2025-04-03 N/A
Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
CVE-2003-0622 1 Bea 2 Tuxedo, Weblogic Server 2025-04-03 N/A
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.
CVE-2000-0609 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
CVE-1999-1055 1 Microsoft 1 Excel 2025-04-03 N/A
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."