Vulnerabilities (CVE)

Total 255086 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0577 1 Lexmark 1 X1185 2024-02-04 7.2 HIGH N/A
Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the "Appearance" dialog and selecting the "Additional styles (skins) are available on the Lexmark web site" option, which launches a web browser that is running with SYSTEM privileges.
CVE-2005-3376 1 Kaspersky Lab 1 Kaspersky Anti-virus 2024-02-04 5.1 MEDIUM N/A
Multiple interpretation error in Kaspersky 5.0.372 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
CVE-2005-1607 1 Remote Cart 1 Remote Cart 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.
CVE-2006-3721 1 Oracle 1 Enterprise Manager 2024-02-04 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Oracle Management Service for Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors, aka Oracle Vuln# EM03 and EM04.
CVE-2005-2043 1 Xampp 1 Apache Distribution 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.
CVE-2004-1226 1 Sugarcrm 1 Sugarcrm 2024-02-04 5.0 MEDIUM N/A
SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.
CVE-2005-0476 1 Hpm Guestbook.cgi 1 Hpm Guestbook.cgi 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.
CVE-2005-1591 1 Sun 2 Solaris, Sunos 2024-02-04 5.0 MEDIUM N/A
Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.
CVE-2005-3650 1 First4internet Xcp Drm 1 First4internet Xcp Drm 2024-02-04 9.3 HIGH N/A
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
CVE-2005-0277 1 3com 1 3cdaemon 2024-02-04 5.0 MEDIUM N/A
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.
CVE-2005-4255 1 Wikkawiki 1 Wikkawiki 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.
CVE-2005-3253 2 Avaya, Proxim 10 Wireless Ap-3, Wireless Ap-4, Wireless Ap-5 and 7 more 2024-02-04 7.5 HIGH N/A
Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "12345", which allows remote attackers to bypass authentication.
CVE-2006-3737 1 Swsoft 1 Plesk Control Panel 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.
CVE-2005-1316 1 Horde 1 Accounts 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
CVE-2006-3739 2 X.org, Xfree86 Project 2 X.org, Xfree86 X 2024-02-04 7.2 HIGH N/A
Integer overflow in the CIDAFM function in X.Org 6.8.2 and XFree86 X server allows local users to execute arbitrary code via crafted Adobe Font Metrics (AFM) files with a modified number of character metrics (StartCharMetrics), which leads to a heap-based buffer overflow.
CVE-2006-1387 1 Twiki 1 Twiki 2024-02-04 4.0 MEDIUM N/A
TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.
CVE-2006-3388 1 Phpmyadmin 1 Phpmyadmin 2024-02-04 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.
CVE-2006-1333 1 Betaparticle 1 Betaparticle Blog 2024-02-04 6.4 MEDIUM N/A
Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.
CVE-2006-1684 1 Ecotwo 1 Shopsystem 2024-02-04 5.0 MEDIUM N/A
Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors.
CVE-2006-0221 1 Ddsn 1 Cm3cms 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.