Vulnerabilities (CVE)

Total 266734 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0507 1 Concatus 1 Imate Webmail Server 2024-02-28 5.0 MEDIUM N/A
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
CVE-2001-0540 1 Microsoft 1 Terminal Server 2024-02-28 5.0 MEDIUM N/A
Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.
CVE-1999-0564 2024-02-28 10.0 HIGH N/A
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
CVE-2004-2151 1 Virtual Projects 1 Chatman 2024-02-28 5.0 MEDIUM N/A
Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.
CVE-2002-0856 1 Oracle 2 Database Server, Oracle9i 2024-02-28 5.0 MEDIUM N/A
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
CVE-2002-1826 1 Grsecurity 1 Grsecurity Kernel Patch 2024-02-28 4.6 MEDIUM N/A
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.
CVE-1999-0816 1 Motorola 1 Motorola Cablerouter 2024-02-28 10.0 HIGH N/A
The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.
CVE-2002-0926 1 Wolfram Research 1 Webmathematica 2024-02-28 5.0 MEDIUM N/A
Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter.
CVE-2003-1159 1 Plug And Play 1 Plug And Play Web Server Proxy 2024-02-28 5.0 MEDIUM N/A
Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.
CVE-2001-0072 1 Gnu 1 Privacy Guard 2024-02-28 5.0 MEDIUM N/A
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
CVE-2000-1117 1 Ibm 1 Lotus Notes 2024-02-28 5.0 MEDIUM N/A
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
CVE-2003-0514 1 Apple 1 Safari 2024-02-28 7.5 HIGH N/A
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
CVE-2002-0589 1 Steve Korbett 1 Pvote 2024-02-28 7.5 HIGH N/A
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
CVE-2001-0260 1 Lotus 1 Domino Mail Server 2024-02-28 7.5 HIGH N/A
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.
CVE-2002-2210 1 Openoffice 1 Openoffice 2024-02-28 6.2 MEDIUM N/A
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
CVE-2004-1878 1 Linbit Technologies 1 Linbox Officeserver 2024-02-28 5.0 MEDIUM N/A
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).
CVE-2004-1423 1 Php-calendar 1 Php-calendar 2024-02-28 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.
CVE-2003-0197 2 Borland Software, Firebirdsql 2 Interbase, Firebird 2024-02-28 7.2 HIGH N/A
Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).
CVE-1999-1418 1 Mirabilis 1 Icq Web Front 2024-02-28 5.0 MEDIUM N/A
ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").
CVE-2002-0817 1 William Deich 1 Super 2024-02-28 7.2 HIGH N/A
Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.