Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 28799 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6208 1 Enthrallweb 1 Eclassifieds 2024-02-14 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp.
CVE-2005-1187 1 X-ways Software Technology Ag 1 Winhex 2024-02-14 5.1 MEDIUM N/A
Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.
CVE-2005-1467 1 Ethereal Group 1 Ethereal 2024-02-14 5.0 MEDIUM N/A
Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.
CVE-2004-1873 1 Alan Ward 1 A-cart 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.
CVE-2002-0353 1 Ethereal Group 1 Ethereal 2024-02-14 5.0 MEDIUM N/A
The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields.
CVE-2005-3545 1 Ibproarcade 1 Ibproarcade 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.
CVE-1999-1144 1 Hp 1 Hp-ux 2024-02-14 7.2 HIGH N/A
Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.
CVE-2004-0267 1 Broadcom 1 Inoculateit 2024-02-14 2.1 LOW N/A
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.
CVE-2007-3163 1 Frederico Caldeira Knabben 1 Fckeditor 2024-02-14 5.0 MEDIUM N/A
Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.
CVE-2005-1596 1 Fusion 1 Sbx 2024-02-14 10.0 HIGH N/A
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.
CVE-2005-1456 1 Ethereal Group 1 Ethereal 2024-02-14 5.0 MEDIUM N/A
Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).
CVE-2007-4288 1 Microsoft 1 Windows Media Player 2024-02-14 4.3 MEDIUM N/A
Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au.
CVE-2000-0411 1 Matt Wright 1 Formmail 2024-02-14 5.0 MEDIUM N/A
Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.
CVE-2006-0310 1 Mike Helton 1 Aoblogger 2024-02-14 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.
CVE-2005-2840 1 Maxdev 1 Md-pro 2024-02-14 10.0 HIGH N/A
Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2) Search, (3) Web links, (4) Blocks, (5) Messages, (6) News, (7) Comments, (8) Settings, (9) Stats or (10) subjects modules.
CVE-2004-0029 1 Ibm 1 Lotus Domino 2024-02-14 4.6 MEDIUM N/A
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
CVE-2006-3313 1 Netsoft 1 Smartnet 2024-02-14 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.
CVE-2005-1904 1 Jiro 1 Jiro Upload System 2024-02-14 7.5 HIGH N/A
SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2006-1936 1 Ethereal Group 1 Ethereal 2024-02-14 5.0 MEDIUM N/A
Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.
CVE-2001-1193 1 Khamil Landross And Zack Jones 1 Eftp 2024-02-14 5.0 MEDIUM N/A
Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command.