Vulnerabilities (CVE)

Total 254946 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2445 1 Linux 1 Linux Kernel 2024-02-04 4.0 MEDIUM N/A
Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.
CVE-2005-2243 1 Cisco 1 Call Manager 2024-02-04 5.0 MEDIUM N/A
Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail.
CVE-2006-3782 1 Sun 1 Solaris 2024-02-04 4.9 MEDIUM N/A
Unspecified vulnerability in the kernel debugger (kmdb) in Sun Solaris 10, when running on x86, allows local users to cause a denial of service (system hang) via unspecified vectors.
CVE-2006-1212 1 Corenews 1 Corenews 2024-02-04 7.5 HIGH N/A
Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use a "page" parameter or variable.
CVE-2005-4754 1 Bea 1 Weblogic Server 2024-02-04 5.0 MEDIUM N/A
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation."
CVE-2006-1500 1 Tilde 1 Tilde Cms 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2005-3293 1 Xerver 1 Xerver 2024-02-04 5.0 MEDIUM N/A
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.
CVE-2005-1354 1 Forum.pl 1 Forum.pl 2024-02-04 7.5 HIGH N/A
The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
CVE-2005-2686 1 Savewebportal 1 Savewebportal 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.
CVE-2006-2250 1 Cutephp 1 Cutenews 2024-02-04 6.4 MEDIUM N/A
CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message.
CVE-2005-1899 1 Rakkarsoft 1 Raknet 2024-02-04 5.0 MEDIUM N/A
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.
CVE-2006-0359 1 Counterpath 1 Eyebeam Sip Softphone 2024-02-04 7.5 HIGH N/A
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.
CVE-2006-3593 1 Cisco 1 Unified Callmanager 2024-02-04 4.0 MEDIUM N/A
The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.
CVE-2005-4013 1 Php Web 1 Statistik 2024-02-04 5.0 MEDIUM N/A
PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.
CVE-2005-4190 1 Horde 1 Horde Application Framework 2024-02-04 3.5 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.
CVE-2005-4027 1 Simplemedia 1 Simplebbs 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
CVE-2006-2660 1 Php 1 Php 2024-02-04 2.1 LOW N/A
Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename.
CVE-2006-2163 1 Desert Dog Software 1 Pinnacle Cart 2024-02-04 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.
CVE-2005-0314 1 Amax Information Technologies 1 Magic Winmail Server 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.
CVE-2005-2002 1 Mambo 1 Mambo 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.