Vulnerabilities (CVE)

Total 259268 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1720 1 Merak 1 Mail Server 2024-02-04 5.0 MEDIUM N/A
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.
CVE-2003-0556 1 Polycom 3 Mgc-100, Mgc-25, Mgc-50 2024-02-04 5.0 MEDIUM N/A
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
CVE-2003-0941 1 Sap 1 Sap Db 2024-02-04 7.5 HIGH N/A
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.
CVE-2004-2029 1 Trevor Hogan 1 Bnbt 2024-02-04 5.0 MEDIUM N/A
The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.
CVE-2003-0179 1 Ibm 2 Lotus Domino Web Server, Lotus Notes Client 2024-02-04 7.5 HIGH N/A
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
CVE-2002-0970 1 Kde 2 Kde, Konqueror 2024-02-04 7.5 HIGH N/A
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
CVE-2003-0418 1 Linux 1 Linux Kernel 2024-02-04 5.0 MEDIUM N/A
The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
CVE-2002-0644 1 Microsoft 2 Data Engine, Sql Server 2024-02-04 7.5 HIGH N/A
Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
CVE-1999-0668 1 Microsoft 1 Internet Explorer 2024-02-04 5.1 MEDIUM N/A
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
CVE-2004-2056 1 Nucleus Group 1 Nucleus Cms 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.
CVE-2002-0730 1 Philip Chinery 1 Philip Chinerys Guestbook 2024-02-04 7.5 HIGH N/A
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.
CVE-2004-2211 1 Alivesites 1 Alivesites Forum 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp.
CVE-2002-0965 1 Oracle 1 Oracle9i 2024-02-04 7.5 HIGH N/A
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.
CVE-2001-1508 1 Sco 1 Openserver 2024-02-04 4.6 MEDIUM N/A
Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.
CVE-1999-0539 2024-02-04 10.0 HIGH N/A
A trust relationship exists between two Unix hosts.
CVE-2003-0298 1 Mozilla 1 Mozilla 2024-02-04 7.5 HIGH N/A
The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
CVE-2000-0909 1 University Of Washington 1 Pine 2024-02-04 7.5 HIGH N/A
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
CVE-2003-0260 1 Cisco 6 Vpn 3000 Concentrator Series Software, Vpn 3002 Hardware Client, Vpn 3015 Concentrator and 3 more 2024-02-04 5.0 MEDIUM N/A
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.
CVE-2004-0720 1 Apple 1 Safari 2024-02-04 7.5 HIGH N/A
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
CVE-2001-0351 1 Microsoft 1 Windows 2000 2024-02-04 2.1 LOW N/A
Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.