Vulnerabilities (CVE)

Total 258583 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1053 2 Apache, Matt Wright 2 Http Server, Matt Wright Guestbook 2008-09-05 7.5 HIGH N/A
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
CVE-1999-1051 1 Matt Wright 1 Formhandler.cgi 2008-09-05 5.0 MEDIUM N/A
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
CVE-1999-1042 1 Cisco 1 Resource Manager 2008-09-05 1.2 LOW N/A
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
CVE-1999-1012 1 Lotus 1 Domino 2008-09-05 5.0 MEDIUM N/A
SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.
CVE-1999-0997 3 Millenux Gmbh, Redhat, University Of Washington 3 Anonftp, Linux, Wu-ftpd 2008-09-05 7.5 HIGH N/A
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
CVE-1999-0992 1 Hp 1 Vvos 2008-09-05 10.0 HIGH N/A
HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).
CVE-1999-0926 1 Apache 1 Http Server 2008-09-05 10.0 HIGH N/A
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
CVE-1999-0923 1 Allaire 1 Coldfusion Server 2008-09-05 7.5 HIGH N/A
Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.
CVE-1999-0784 1 Oracle 1 Database Server 2008-09-05 5.0 MEDIUM N/A
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
CVE-1999-0744 1 Netscape 2 Enterprise Server, Fasttrack Server 2008-09-05 7.5 HIGH N/A
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
CVE-1999-0477 1 Allaire 1 Coldfusion Server 2008-09-05 7.5 HIGH N/A
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
CVE-1999-0460 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
CVE-1999-0451 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
CVE-1999-0400 1 Linux 1 Linux Kernel 2008-09-05 4.6 MEDIUM N/A
Denial of service in Linux 2.2.0 running the ldd command on a core file.
CVE-1999-0299 1 Freebsd 1 Freebsd 2008-09-05 9.3 HIGH N/A
Buffer overflow in FreeBSD lpd through long DNS hostnames.
CVE-1999-0248 1 Ssh 1 Ssh 2008-09-05 10.0 HIGH N/A
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
CVE-1999-0053 1 Freebsd 1 Freebsd 2008-09-05 5.0 MEDIUM N/A
TCP RST denial of service in FreeBSD.
CVE-2008-3937 1 Opendb 1 Opendb 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.
CVE-2008-3939 1 Avtech 1 Pager Enterprise 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
CVE-2008-3935 1 D-ic 2 Shop V50, Shop V52 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.