Vulnerabilities (CVE)

Total 258949 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0170 1 Digital 1 Ultrix 2024-02-04 7.5 HIGH N/A
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
CVE-2002-1838 1 Steve Sachs 1 Charities.cron 2024-02-04 5.0 MEDIUM N/A
Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.
CVE-2002-0417 1 Endymion 1 Mailman Webmail 2024-02-04 5.0 MEDIUM N/A
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.
CVE-2002-1064 1 T. Hauck 1 Jana Web Server 2024-02-04 5.0 MEDIUM N/A
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
CVE-2001-1475 1 Ssh 1 Ssh 2024-02-04 7.5 HIGH N/A
SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.
CVE-2001-0943 1 Oracle 1 Database Server 2024-02-04 7.2 HIGH N/A
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
CVE-2002-0588 1 Steve Korbett 1 Pvote 2024-02-04 5.0 MEDIUM N/A
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
CVE-2001-0441 3 Debian, Mandrakesoft, Redhat 4 Debian Linux, Mandrake Linux, Mandrake Linux Corporate Server and 1 more 2024-02-04 7.5 HIGH N/A
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
CVE-2004-2152 1 Mediawiki 1 Mediawiki 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.
CVE-2001-1545 1 Macromedia 1 Jrun 2024-02-04 5.0 MEDIUM N/A
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
CVE-2004-0485 1 Apple 1 Mac Os X 2024-02-04 5.0 MEDIUM N/A
The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.
CVE-2002-0580 1 Workforceroi 1 Xpede 2024-02-04 7.5 HIGH N/A
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.
CVE-2001-0494 1 Ipswitch 1 Imail 2024-02-04 7.5 HIGH N/A
Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.
CVE-2003-0307 1 Poster 1 Poster 2024-02-04 7.5 HIGH N/A
Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.
CVE-2001-0591 1 Oracle 2 Application Server, Jsp 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
CVE-1999-1014 1 Sun 2 Solaris, Sunos 2024-02-04 4.6 MEDIUM N/A
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
CVE-2001-0127 1 Oliver Debon 1 Flash 2024-02-04 7.6 HIGH N/A
Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.
CVE-2001-1128 1 Progress 1 Progress 2024-02-04 7.2 HIGH N/A
Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables.
CVE-2000-0866 1 Borland Software 1 Interbase Superserver 2024-02-04 2.1 LOW N/A
Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.
CVE-2002-0317 1 Gator 1 Gator 2024-02-04 7.5 HIGH N/A
Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.