Vulnerabilities (CVE)

Total 255237 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1250 1 Ipswitch 1 Whatsup 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).
CVE-2005-3580 1 Qdbm 1 Qdbm 2024-02-04 7.2 HIGH N/A
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
CVE-2005-0453 1 Lighttpd 1 Lighttpd 2024-02-04 5.0 MEDIUM N/A
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
CVE-2004-2484 1 Php Gift Registry 1 Phpgiftreg 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.
CVE-2005-3578 1 Walla Telesite 1 Walla Telesite 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
CVE-2006-4353 1 Sun 1 Java System Content Delivery Server 2024-02-04 5.0 MEDIUM N/A
Unspecified vulnerability in Sun Java System Content Delivery Server 4.0, 4.1, and 5.0 allows local and remote attackers to read data from arbitrary files via unspecified vectors.
CVE-2005-4014 1 Php Web 1 Statistik 2024-02-04 7.8 HIGH N/A
stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large lastnumber value.
CVE-2005-2329 1 Mrv Communications 3 In Reach Lx 1000s, In Reach Lx 4000s, In Reach Lx 8000s 2024-02-04 4.6 MEDIUM N/A
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.
CVE-2005-1593 1 Codethat 1 Shoppingcart 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2005-4355 1 Xmpie 1 Ustore 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in UStore allow remote attackers to inject arbitrary web script or HTML via the (1) Cat parameter in default.asp and the (2) accessdenied parameter in admin/default.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-0752 1 Mozilla 1 Firefox 2024-02-04 7.5 HIGH N/A
The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
CVE-2006-2834 1 Gnopaste 1 Gnopaste 2024-02-04 7.5 HIGH N/A
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
CVE-2006-0303 1 Joomla 1 Joomla 2024-02-04 10.0 HIGH N/A
Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.
CVE-2005-0070 1 Synaesthesia 1 Synaesthesia 2024-02-04 7.2 HIGH N/A
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.
CVE-2006-2222 1 Norz 1 Zawhttpd 2024-02-04 5.0 MEDIUM N/A
Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) characters.
CVE-2005-0632 1 Phpnews 1 Phpnews 2024-02-04 5.0 MEDIUM N/A
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
CVE-2005-3945 1 Microsoft 2 Windows 2000, Windows 2003 Server 2024-02-04 7.8 HIGH N/A
The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
CVE-2005-1177 2 Usermin, Webmin 2 Usermin, Webmin 2024-02-04 10.0 HIGH N/A
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
CVE-2005-2712 1 Ibm 1 Lotus Domino 2024-02-04 7.8 HIGH N/A
The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
CVE-2006-3023 1 Uapplication 1 Uphotogallery 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) block parameters.