Vulnerabilities (CVE)

Total 253987 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1965 1 Openbb 1 Openbb 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.
CVE-2002-1354 1 Typsoft 1 Typsoft Ftp Server 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.
CVE-2002-1387 1 Ehud Gavron 1 Tracesroute 2024-02-04 4.6 MEDIUM N/A
The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.
CVE-2003-0530 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 7.5 HIGH N/A
Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.
CVE-1999-0444 1 Microsoft 3 Windows 95, Windows 98, Windows Nt 2024-02-04 5.0 MEDIUM N/A
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
CVE-1999-0569 2024-02-04 10.0 HIGH N/A
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
CVE-2001-1497 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 2.1 LOW N/A
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
CVE-2002-0209 1 Nortel 1 Alteon Acedirector 2024-02-04 5.0 MEDIUM N/A
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send packets from the server without changing the address to the virtual IP address.
CVE-2004-1616 1 Links 1 Links 2024-02-04 5.0 MEDIUM N/A
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.
CVE-2003-1288 1 Vserver 1 Linux-vserver 2024-02-04 5.0 MEDIUM N/A
Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions.
CVE-2002-1188 1 Microsoft 1 Internet Explorer 2024-02-04 6.4 MEDIUM N/A
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."
CVE-2002-1743 1 Mirabilis 1 Icq 2024-02-04 5.0 MEDIUM N/A
AOL ICQ 2002a Build 3722 allows remote attackers to cause a denial of service (crash) via a malformed .hpf file.
CVE-2001-1377 11 Freeradius, Gnu, Icradius and 8 more 11 Freeradius, Radius, Icradius and 8 more 2024-02-04 5.0 MEDIUM N/A
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
CVE-2004-0329 1 Freechat 1 Freechat 2024-02-04 5.0 MEDIUM N/A
FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".
CVE-1999-1546 1 Ibm 1 Navio Nc Browser 2024-02-04 5.0 MEDIUM N/A
netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.
CVE-1999-1010 1 Openbsd 1 Openssh 2024-02-04 2.1 LOW N/A
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
CVE-2002-0780 1 Novell 1 Bordermanager 2024-02-04 5.0 MEDIUM N/A
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.
CVE-2000-1053 1 Macromedia 1 Jrun 2024-02-04 10.0 HIGH N/A
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.
CVE-2001-0068 1 Apple 1 Mac Os Runtime For Java 2024-02-04 2.6 LOW N/A
Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.
CVE-2004-1641 1 South River Technologies 1 Titan Ftp Server 2024-02-04 5.0 MEDIUM N/A
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.