Vulnerabilities (CVE)

Total 254267 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0642 1 Microsoft 2 Msde, Sql Server 2024-02-04 7.2 HIGH N/A
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
CVE-2002-2012 1 Apache 1 Http Server 2024-02-04 5.0 MEDIUM N/A
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
CVE-2004-1962 1 Protector System 1 Protector System 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.
CVE-1999-1264 1 Ramp Networks 1 Webramp 2024-02-04 7.5 HIGH N/A
WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.
CVE-2002-0124 1 Mdg Computer Services 1 Web Server 4d Ecommerce 2024-02-04 5.0 MEDIUM N/A
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
CVE-2004-0722 2 Mozilla, Netscape 2 Mozilla, Navigator 2024-02-04 10.0 HIGH N/A
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
CVE-2004-0627 1 Mysql 1 Mysql 2024-02-04 10.0 HIGH N/A
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
CVE-2000-1169 1 Openbsd 1 Openssh 2024-02-04 7.5 HIGH N/A
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.
CVE-1999-0615 2024-02-04 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SNMP service is running."
CVE-2001-1352 1 Namazu 1 Namazu 2024-02-04 7.5 HIGH N/A
Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.
CVE-2002-1968 1 Com21 1 Doxport 1100 2024-02-04 2.1 LOW N/A
Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server.
CVE-2002-1659 1 Iatek 1 Portalapp 2024-02-04 10.0 HIGH N/A
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.
CVE-2001-0502 1 Microsoft 1 Windows 2000 2024-02-04 4.6 MEDIUM N/A
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.
CVE-2000-0396 1 Pacific Software 1 Carello 2024-02-04 5.0 MEDIUM N/A
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.
CVE-2001-0451 1 Sentraweb 1 Indexu 2024-02-04 7.5 HIGH N/A
INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.
CVE-2000-0590 1 Cgi-world 1 Poll It 2024-02-04 7.5 HIGH N/A
Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.
CVE-2000-0960 1 Netscape 1 Messaging Server 2024-02-04 5.0 MEDIUM N/A
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
CVE-2004-1241 2024-02-04 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none.
CVE-2002-1288 1 Microsoft 1 Java Virtual Machine 2024-02-04 5.0 MEDIUM N/A
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.
CVE-2004-0150 1 Python 1 Python 2024-02-04 7.5 HIGH N/A
Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.