Vulnerabilities (CVE)

Total 254557 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-1029 1 Isc 1 Bind 2024-02-04 10.0 HIGH N/A
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.
CVE-2003-0961 1 Linux 1 Linux Kernel 2024-02-04 7.2 HIGH N/A
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
CVE-2004-1166 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 7.5 HIGH N/A
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
CVE-2001-0806 1 Apple 1 Mac Os X 2024-02-04 3.6 LOW N/A
Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.
CVE-2004-0330 1 Solarwinds 1 Serv-u File Server 2024-02-04 10.0 HIGH N/A
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
CVE-2000-1066 1 Freebsd 1 Freebsd 2024-02-04 5.0 MEDIUM N/A
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.
CVE-2002-1941 1 Radiobird Software 1 Web Server 4 Everyone 2024-02-04 5.0 MEDIUM N/A
Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.
CVE-2004-0358 1 Virtuasystems 1 Virtuanews Pro 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.
CVE-2003-1547 1 Francisco Burzi 1 Php-nuke 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.
CVE-2004-1936 1 Zonelabs 1 Zonealarm 2024-02-04 7.5 HIGH N/A
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.
CVE-2002-1030 1 Bea 1 Weblogic Server 2024-02-04 2.6 LOW N/A
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
CVE-2001-0765 1 Bisonware 1 Bison Ftp Server 2024-02-04 4.6 MEDIUM N/A
BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.
CVE-1999-1502 1 Id Software 1 Quake 2024-02-04 7.5 HIGH N/A
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.
CVE-2004-1432 1 Cisco 1 Optical Networking Systems Software 2024-02-04 5.0 MEDIUM N/A
Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or (2) ICMP packets.
CVE-1999-1048 2 Debian, Redhat 2 Debian Linux, Linux 2024-02-04 4.6 MEDIUM N/A
Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.
CVE-2001-0731 1 Apache 1 Http Server 2024-02-04 5.0 MEDIUM N/A
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
CVE-2004-0359 1 Invision Power Services 1 Invision Board 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.
CVE-2004-1353 1 Sun 2 Solaris, Sunos 2024-02-04 7.2 HIGH N/A
Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.
CVE-2001-1311 1 Ibm 1 Lotus Domino R5 2024-02-04 7.5 HIGH N/A
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2003-0310 1 Ez 1 Ez Publish 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.