Search Results (29815 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-1999-0686 2 Hp, Netscape 2 Hp-ux, Enterprise Server 2025-04-03 N/A
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
CVE-2005-1755 1 Php Poll Creator 1 Php Poll Creator 2025-04-03 N/A
PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.
CVE-2005-4666 1 Phlymail 1 Phlymail 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.
CVE-2005-4668 1 Parosproxy 1 Parosproxy 2025-04-03 N/A
The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.
CVE-1999-0687 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2025-04-03 N/A
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-1999-0688 1 Hp 1 Hp-ux 2025-04-03 N/A
Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
CVE-1999-0690 2 Cde, Hp 2 Cde, Hp-ux 2025-04-03 N/A
HP CDE program includes the current directory in root's PATH variable.
CVE-2002-0447 1 Xerver 1 Xerver 2025-04-03 N/A
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request.
CVE-2005-4135 1 Simplemedia 1 Simplebbs 2025-04-03 N/A
Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.
CVE-1999-0692 2 Cray, Sgi 2 Unicos, Irix 2025-04-03 N/A
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
CVE-2002-0450 1 Talentsoft 1 Web\+ Server 2025-04-03 N/A
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.
CVE-2005-4136 1 Fad Solutions 1 Drzes Hms 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.
CVE-1999-0696 2 Hp, Sun 3 Hp-ux, Solaris, Sunos 2025-04-03 N/A
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
CVE-1999-0698 2025-04-03 N/A
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.
CVE-1999-0699 1 Bluestone 1 Sapphire Web 2025-04-03 N/A
The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.
CVE-2005-4144 1 Lyris 1 List Manager 2025-04-03 N/A
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.
CVE-2001-1159 1 Squirrelmail 1 Squirrelmail 2025-04-03 N/A
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.
CVE-2006-4441 1 Ay System Solutions 1 Ay System Solutions Cms 2025-04-03 N/A
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path[ShowProcessHandle] parameter to (1) home.php or (2) impressum.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2004-1629 1 Distinct Web Creations 1 Dwc Articles 2025-04-03 N/A
Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.
CVE-2005-4133 1 Sun 1 Solaris 2025-04-03 N/A
Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.