Vulnerabilities (CVE)

Total 258813 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-1035 1 Typsoft 1 Typsoft 2024-02-04 10.0 HIGH N/A
Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.
CVE-2002-1311 1 Double Precision Incorporated 1 Courier Mta 2024-02-04 4.6 MEDIUM N/A
Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.
CVE-2001-1277 1 Wolfram Schneider 1 Makewhatis 2024-02-04 2.1 LOW N/A
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.
CVE-2002-2203 1 Sun 2 Solaris, Sunos 2024-02-04 4.9 MEDIUM N/A
Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.
CVE-2001-0546 1 Microsoft 1 Isa Server 2024-02-04 5.0 MEDIUM N/A
Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
CVE-2001-0994 1 Marconi 1 Forethought 2024-02-04 5.0 MEDIUM N/A
Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.
CVE-2002-2258 1 Mobydisk 1 Netsuite 2024-02-04 5.0 MEDIUM N/A
Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value in the Content-Length header, which causes an access violation after a failed atoi function call.
CVE-2002-0981 1 Caldera 2 Openunix, Unixware 2024-02-04 7.2 HIGH N/A
Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.
CVE-2001-0313 1 Borderware 1 Firewall Server 2024-02-04 5.0 MEDIUM N/A
Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.
CVE-2002-0153 1 Microsoft 1 Ie 2024-02-04 7.5 HIGH N/A
Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.
CVE-2001-0422 1 Sun 2 Solaris, Sunos 2024-02-04 7.2 HIGH N/A
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
CVE-2002-2193 1 Mojo Mail 1 Mojo Mail 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.
CVE-2003-0965 1 Gnu 1 Mailman 2024-02-04 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.
CVE-2004-1400 1 Active Server Corner 1 Asp Calendar 2024-02-04 7.5 HIGH N/A
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.
CVE-1999-0970 1 Omnicron 1 Omnihttpd 2024-02-04 5.0 MEDIUM N/A
The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.
CVE-1999-0634 2024-02-04 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "The SSH service is running."
CVE-2002-1009 1 Summit Computer Networks 1 Lil Http Server 2024-02-04 7.5 HIGH N/A
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.
CVE-2003-0315 1 Snowblind.net 1 Snowblind Web Server 2024-02-04 7.5 HIGH N/A
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.
CVE-2003-0464 1 Redhat 1 Linux 2024-02-04 4.6 MEDIUM N/A
The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
CVE-2003-0987 1 Apache 1 Http Server 2024-02-04 7.5 HIGH N/A
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.