Vulnerabilities (CVE)

Total 253345 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0064 1 Nortel 1 Contivity 2024-02-04 5.0 MEDIUM N/A
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.
CVE-1999-1540 1 Cactus Software 1 Shell-lock 2024-02-04 2.1 LOW N/A
shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.
CVE-2002-0030 1 Adobe 2 Acrobat, Acrobat Reader 2024-02-04 4.6 MEDIUM N/A
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.
CVE-2000-1095 5 Conectiva, Immunix, Mandrakesoft and 2 more 5 Linux, Immunix, Mandrake Linux and 2 more 2024-02-04 7.2 HIGH N/A
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
CVE-2002-0825 1 Padl Software 1 Nss Ldap 2024-02-04 7.5 HIGH N/A
Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2004-0056 1 Nortel 3 802.11 Wireless Ip Gateway, Business Communications Manager, Succession Communication Server 1000 2024-02-04 7.5 HIGH N/A
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
CVE-2003-0720 1 University Of Washington 1 Pine 2024-02-04 7.5 HIGH N/A
Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
CVE-2004-1519 1 Benjamin Curtis 1 Phpbugtracker 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.
CVE-2001-0910 1 Emc 1 Networker 2024-02-04 7.5 HIGH N/A
Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup.
CVE-2001-0891 2 Cray, Sgi 2 Unicos, Nqsdaemon 2024-02-04 7.2 HIGH N/A
Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
CVE-2002-2357 1 Mailenable 1 Mailenable 2024-02-04 5.0 MEDIUM N/A
MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overflow.
CVE-2002-0154 1 Microsoft 1 Sql Server 2024-02-04 7.5 HIGH N/A
Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
CVE-2002-2389 1 Fastlink Software 1 The Server 2024-02-04 5.0 MEDIUM N/A
TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows remote attackers to obtain cleartext passwords and gain access to server log files.
CVE-1999-0774 1 Martin Stover 1 Mars Nwe 2024-02-04 7.2 HIGH N/A
Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
CVE-2003-0218 1 Monkey-project 1 Monkey 2024-02-04 7.5 HIGH N/A
Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.
CVE-2000-0226 1 Microsoft 1 Internet Information Server 2024-02-04 5.0 MEDIUM N/A
IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."
CVE-1999-1277 1 Backweb Technologies 1 Backweb Client 2024-02-04 4.6 MEDIUM N/A
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
CVE-2001-0060 1 Stunnel 1 Stunnel 2024-02-04 10.0 HIGH N/A
Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.
CVE-2001-1282 1 Ipswitch 1 Imail 2024-02-04 5.0 MEDIUM N/A
Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.
CVE-2002-0777 1 Ipswitch 1 Imail 2024-02-04 10.0 HIGH N/A
Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.