Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 28764 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1747 1 Vwar 1 Virtual War 2024-02-14 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.
CVE-2001-0949 1 Valicert 1 Enterprise Validation Authority 2024-02-14 7.5 HIGH N/A
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.
CVE-2005-1329 1 Oneworldstore 1 Oneworldstore 2024-02-14 5.0 MEDIUM N/A
owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.
CVE-2006-3250 1 Microsoft 1 Windows Live Messenger 2024-02-14 5.1 MEDIUM N/A
Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is imported by the user.
CVE-2003-0429 1 Ethereal Group 1 Ethereal 2024-02-14 7.5 HIGH N/A
The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.
CVE-2002-0732 1 Levcgi.com 1 Myguestbook 2024-02-14 7.5 HIGH N/A
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments.
CVE-2005-1162 1 Oneworldstore 1 Oneworldstore 2024-02-14 5.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.
CVE-2006-6082 1 Creascripts 1 Creadirectory 2024-02-14 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
CVE-1999-1249 1 Hp 1 Hp-ux 2024-02-14 4.6 MEDIUM N/A
movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.
CVE-2003-0927 1 Ethereal Group 1 Ethereal 2024-02-14 7.5 HIGH N/A
Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.
CVE-2007-1324 1 Snapgear 6 560, 580, 585 and 3 more 2024-02-14 5.0 MEDIUM N/A
SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.
CVE-2004-0267 1 Broadcom 1 Inoculateit 2024-02-14 2.1 LOW N/A
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.
CVE-2003-0357 1 Ethereal Group 1 Ethereal 2024-02-14 7.5 HIGH N/A
Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.
CVE-2005-1805 1 Online Solutions For Educators 1 Online Solutions For Educators 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.
CVE-2006-1936 1 Ethereal Group 1 Ethereal 2024-02-14 5.0 MEDIUM N/A
Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.
CVE-2002-0821 1 Ethereal Group 1 Ethereal 2024-02-14 7.5 HIGH N/A
Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector.
CVE-2006-6838 1 Rediff 1 Bol Downloader Activex Ocx Control 2024-02-14 7.5 HIGH N/A
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.
CVE-2006-3205 1 Ultimate Php Board 1 Ultimate Php Board 2024-02-14 5.0 MEDIUM N/A
Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.
CVE-2005-3159 1 Php Fusion 1 Php Fusion 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
CVE-2001-1367 1 Phpslice 1 Phpslice 2024-02-14 10.0 HIGH N/A
The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges.