Vulnerabilities (CVE)

Total 266151 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1136 1 Hp 1 Hp-ux 2024-02-28 2.1 LOW N/A
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.
CVE-2001-0465 1 Intuit 1 Turbo Tax 2024-02-28 4.6 MEDIUM N/A
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.
CVE-2001-0422 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
CVE-2002-1993 1 Affordable Web Space Design 1 Affordable Web Space Design Webbbs 2024-02-28 10.0 HIGH N/A
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.
CVE-2002-0537 1 Stepweb 1 Sws 2024-02-28 10.0 HIGH N/A
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.
CVE-2004-2248 1 Goosequill 1 Remoteeditor 2024-02-28 10.0 HIGH N/A
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."
CVE-2004-1773 1 Gnu 1 Sharutils 2024-02-28 7.5 HIGH N/A
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
CVE-2001-1332 1 Easy Software Products 1 Cups 2024-02-28 7.5 HIGH N/A
Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.
CVE-2002-1730 1 Aspjar 1 Aspjar Guestbook 2024-02-28 5.0 MEDIUM N/A
ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true".
CVE-2002-1749 1 Microsoft 1 Windows 2000 2024-02-28 7.2 HIGH N/A
Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges.
CVE-2003-0033 1 Snort 1 Snort 2024-02-28 10.0 HIGH N/A
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.
CVE-2003-0057 1 Hypermail 1 Hypermail 2024-02-28 7.5 HIGH N/A
Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.
CVE-2001-0271 1 Mailnews.cgi 1 Mailnews.cgi 2024-02-28 10.0 HIGH N/A
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.
CVE-2002-0311 1 Caldera 2 Openunix, Unixware 2024-02-28 10.0 HIGH N/A
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.
CVE-2000-0546 3 Cygnus Network Security Project, Kerbnet Project, Mit 4 Cygnus Network Security, Kerbnet, Kerberos and 1 more 2024-02-28 5.0 MEDIUM N/A
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
CVE-1999-1490 1 Redhat 1 Linux 2024-02-28 7.2 HIGH N/A
xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.
CVE-2001-1204 1 Total Pc Solutions 1 Php Rocket Add-in 2024-02-28 5.0 MEDIUM N/A
Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
CVE-2002-2182 1 Seunghyun Seo 1 Msn666 2024-02-28 6.4 MEDIUM N/A
Buffer overflow in Seunghyun Seo's MSN666 MSN Sniffer 1.0 and 1.0.1 allows remote attackers to execute arbitrary code via a long MSN packet.
CVE-2004-1730 1 Mantis 1 Mantis 2024-02-28 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.
CVE-2004-2021 1 Oscommerce 1 Oscommerce 2024-02-28 5.0 MEDIUM N/A
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.