Total
28799 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-6208 | 1 Enthrallweb | 1 Eclassifieds | 2024-02-14 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp. | |||||
CVE-2005-1187 | 1 X-ways Software Technology Ag | 1 Winhex | 2024-02-14 | 5.1 MEDIUM | N/A |
Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability. | |||||
CVE-2005-1467 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors. | |||||
CVE-2004-1873 | 1 Alan Ward | 1 A-cart | 2024-02-14 | 7.5 HIGH | N/A |
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. | |||||
CVE-2002-0353 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields. | |||||
CVE-2005-3545 | 1 Ibproarcade | 1 Ibproarcade | 2024-02-14 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter. | |||||
CVE-1999-1144 | 1 Hp | 1 Hp-ux | 2024-02-14 | 7.2 HIGH | N/A |
Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges. | |||||
CVE-2004-0267 | 1 Broadcom | 1 Inoculateit | 2024-02-14 | 2.1 LOW | N/A |
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp. | |||||
CVE-2007-3163 | 1 Frederico Caldeira Knabben | 1 Fckeditor | 2024-02-14 | 5.0 MEDIUM | N/A |
Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658. | |||||
CVE-2005-1596 | 1 Fusion | 1 Sbx | 2024-02-14 | 10.0 HIGH | N/A |
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter. | |||||
CVE-2005-1456 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort). | |||||
CVE-2007-4288 | 1 Microsoft | 1 Windows Media Player | 2024-02-14 | 4.3 MEDIUM | N/A |
Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au. | |||||
CVE-2000-0411 | 1 Matt Wright | 1 Formmail | 2024-02-14 | 5.0 MEDIUM | N/A |
Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | |||||
CVE-2006-0310 | 1 Mike Helton | 1 Aoblogger | 2024-02-14 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag. | |||||
CVE-2005-2840 | 1 Maxdev | 1 Md-pro | 2024-02-14 | 10.0 HIGH | N/A |
Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2) Search, (3) Web links, (4) Blocks, (5) Messages, (6) News, (7) Comments, (8) Settings, (9) Stats or (10) subjects modules. | |||||
CVE-2004-0029 | 1 Ibm | 1 Lotus Domino | 2024-02-14 | 4.6 MEDIUM | N/A |
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges. | |||||
CVE-2006-3313 | 1 Netsoft | 1 Smartnet | 2024-02-14 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter. | |||||
CVE-2005-1904 | 1 Jiro | 1 Jiro Upload System | 2024-02-14 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |||||
CVE-2006-1936 | 1 Ethereal Group | 1 Ethereal | 2024-02-14 | 5.0 MEDIUM | N/A |
Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector. | |||||
CVE-2001-1193 | 1 Khamil Landross And Zack Jones | 1 Eftp | 2024-02-14 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command. |