Vulnerabilities (CVE)

Total 258811 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1133 1 Bsdi 1 Bsd Os 2024-02-04 2.1 LOW N/A
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.
CVE-2002-2000 1 Compaq 1 Acms 2024-02-04 2.1 LOW N/A
ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data.
CVE-2002-2195 1 Nullsoft 1 Winamp 2024-02-04 5.0 MEDIUM N/A
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
CVE-2004-0447 1 Linux 1 Linux Kernel 2024-02-04 7.2 HIGH N/A
Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact. NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477. This is the proper candidate to use for the Linux local DoS.
CVE-2000-0346 1 Apple 1 Appleshare 2024-02-04 5.0 MEDIUM N/A
AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.
CVE-2001-1114 1 Netcode 1 Nc Book 2024-02-04 7.5 HIGH N/A
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.
CVE-2001-1228 1 Gnu 1 Gzip 2024-02-04 7.5 HIGH N/A
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
CVE-2000-0045 1 Oracle 1 Mysql 2024-02-04 6.4 MEDIUM N/A
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
CVE-2004-0542 1 Php 1 Php 2024-02-04 10.0 HIGH N/A
PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.
CVE-2000-0224 1 Sco 1 Unixware 2024-02-04 1.2 LOW N/A
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
CVE-2002-0894 1 New Atlanta Communications 1 Servletexec Isapi 2024-02-04 5.0 MEDIUM N/A
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.
CVE-2002-1828 1 Savant 1 Savant Webserver 2024-02-04 5.0 MEDIUM N/A
Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.
CVE-2001-1444 1 Kth 1 Kth Kerberos 2024-02-04 7.5 HIGH N/A
The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack.
CVE-2000-0181 1 Checkpoint 1 Firewall-1 2024-02-04 5.0 MEDIUM N/A
Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.
CVE-2000-1153 1 Kenny Carruthers 1 Postmaster 2024-02-04 5.0 MEDIUM N/A
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
CVE-2003-0438 1 Yuuichi Teranishi 1 Eldav 2024-02-04 1.2 LOW N/A
eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
CVE-2004-0335 1 Software602 1 602pro Lan Suite 2024-02-04 5.0 MEDIUM N/A
LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.
CVE-2002-0832 1 Microsoft 1 Internet Explorer 2024-02-04 7.5 HIGH N/A
Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature.
CVE-2004-1499 1 Webhost Automation 1 Helm Control Panel 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
CVE-2000-0190 1 Aol 1 Instant Messenger 2024-02-04 5.0 MEDIUM N/A
AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.