Vulnerabilities (CVE)

Total 253939 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1794 1 Hp 2 Hp-ux, Ldap-ux Integration 2024-02-04 10.0 HIGH N/A
Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.
CVE-2001-0281 1 Microsoft 1 Windows Nt 2024-02-04 7.2 HIGH N/A
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
CVE-2000-0023 1 Lotus 1 Domino Server 2024-02-04 5.0 MEDIUM N/A
Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.
CVE-2002-0846 1 Macromedia 1 Shockwave Flash 2024-02-04 7.5 HIGH N/A
The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.
CVE-1999-0103 2024-02-04 5.0 MEDIUM N/A
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
CVE-2001-0911 2 Francisco Burzi, Postnuke Software Foundation 2 Php-nuke, Postnuke 2024-02-04 7.5 HIGH N/A
PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.
CVE-2003-0749 1 Sap 1 Internet Transaction Server 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.
CVE-1999-0863 1 Freebsd 1 Freebsd 2024-02-04 4.6 MEDIUM N/A
Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.
CVE-2000-0768 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 2.6 LOW N/A
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
CVE-2003-1476 1 Cerberus 1 Ftp Server 2024-02-04 2.1 LOW N/A
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.
CVE-2002-1483 1 Db4web 1 Db4web 2024-02-04 5.0 MEDIUM N/A
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).
CVE-2003-0355 2 Apple, Kde 2 Safari, Konqueror Embedded 2024-02-04 5.0 MEDIUM N/A
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
CVE-2002-1336 1 Tightvnc 1 Tightvnc 2024-02-04 7.5 HIGH N/A
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
CVE-2002-0885 2 Caldera, Sun 3 Openunix, Unixware, Sunos 2024-02-04 7.5 HIGH N/A
Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.
CVE-2002-1257 1 Microsoft 8 Windows 2000, Windows 2000 Terminal Services, Windows 95 and 5 more 2024-02-04 10.0 HIGH N/A
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
CVE-2003-0095 1 Oracle 3 Database Server, Oracle8i, Oracle9i 2024-02-04 10.0 HIGH N/A
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.
CVE-2002-0573 1 Sun 2 Solaris, Sunos 2024-02-04 7.5 HIGH N/A
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
CVE-2001-1343 1 Cgicentral 2 Webstore 400, Webstore 400cs 2024-02-04 7.5 HIGH N/A
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.
CVE-1999-0198 2024-02-04 10.0 HIGH N/A
finger .@host on some systems may print information on some user accounts.
CVE-2002-0887 1 Caldera 1 Openserver 2024-02-04 2.1 LOW N/A
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.