Vulnerabilities (CVE)

Total 266197 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0581 2 Gnu, Mandrakesoft 3 Ksymoops, Mandrake Linux, Mandrake Linux Corporate Server 2024-02-28 4.6 MEDIUM N/A
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
CVE-2000-0692 1 Iss 1 Realsecure 2024-02-28 5.0 MEDIUM N/A
ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.
CVE-2002-1034 1 Sun 1 I-runbook 2024-02-28 10.0 HIGH N/A
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
CVE-2004-0709 1 Hp 1 Openview Select Access 2024-02-28 7.5 HIGH N/A
HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.
CVE-2003-0363 1 Licq 1 Licq 2024-02-28 7.5 HIGH N/A
Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.
CVE-1999-0792 1 Osicom 1 Routermate 2024-02-28 5.0 MEDIUM N/A
ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.
CVE-2001-0997 1 Textor Webmasters Ltd. 1 Listrec.pl 2024-02-28 7.5 HIGH N/A
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.
CVE-2002-1571 1 Linux 1 Linux Kernel 2024-02-28 2.1 LOW N/A
The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.
CVE-2003-0697 1 Ibm 1 Aix 2024-02-28 7.2 HIGH N/A
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
CVE-2002-2089 1 Sun 1 Solaris 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
CVE-2001-0435 1 Pgp 1 Pgp 2024-02-28 4.6 MEDIUM N/A
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.
CVE-2003-1521 1 Sun 1 Java Plug-in 2024-02-28 6.4 MEDIUM N/A
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
CVE-2004-1243 2024-02-28 N/A N/A
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none
CVE-2002-2187 1 Macromedia 1 Jrun 2024-02-28 5.0 MEDIUM N/A
Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.
CVE-2000-1206 1 Apache 1 Http Server 2024-02-28 5.0 MEDIUM N/A
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
CVE-2002-0089 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
CVE-2003-0985 1 Linux 1 Linux Kernel 2024-02-28 7.2 HIGH N/A
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.
CVE-2001-0200 1 Heat-on Software 1 Hsweb 2024-02-28 5.0 MEDIUM N/A
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.
CVE-2003-0844 1 Schroepl 1 Mod Gzip 2024-02-28 2.1 LOW 7.1 HIGH
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
CVE-2002-0763 1 Hp 1 Virtualvault 2024-02-28 7.5 HIGH N/A
Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.