Search Results (29880 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2006-2958 1 Filzip 1 Filzip 2025-04-03 N/A
Directory traversal vulnerability in FilZip 3.05 allows remote attackers to write arbitrary files via a .. (dot dot) in a (1) .rar, (2) .tar, (3) .jar, or (4) .gz file. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2006-2965 1 Particle Soft 1 Particle Whois 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."
CVE-2006-2966 1 Particle Soft 1 Particle Wiki 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS protection scheme.
CVE-2006-2969 1 L0j1k 1 Tinymuw 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations.
CVE-2006-2971 1 Overkill 1 Overkill 2025-04-03 N/A
Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function.
CVE-2006-2974 1 Emailarchitect 1 Email Server 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp.
CVE-2006-2975 1 Pbl Guestbook 1 Pbl Guestbook 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.
CVE-2006-2993 1 My Photo Scrapbook 1 My Photo Scrapbook 2025-04-03 N/A
Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.
CVE-1999-0108 1 Sgi 1 Irix 2025-04-03 N/A
The printers program in IRIX has a buffer overflow that gives root access to local users.
CVE-1999-0140 1 Microsoft 1 Windows Nt 2025-04-03 N/A
Denial of service in RAS/PPTP on NT systems.
CVE-1999-0151 1 Satan 1 Satan 2025-04-03 N/A
The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.
CVE-1999-0175 1 Novell 1 Web Server 2025-04-03 N/A
The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.
CVE-1999-0195 2 Linux, Sgi 2 Linux Kernel, Irix 2025-04-03 N/A
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
CVE-1999-0212 1 Sun 1 Sunos 2025-04-03 N/A
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
CVE-1999-0221 1 Lucent 1 Ascend Routers 2025-04-03 N/A
Denial of service of Ascend routers through port 150 (remote administration).
CVE-1999-0229 1 Microsoft 1 Internet Information Server 2025-04-03 N/A
Denial of service in Windows NT IIS server using ..\..
CVE-1999-0240 2025-04-03 N/A
Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.
CVE-1999-0253 1 Microsoft 2 Internet Information Server, Internet Information Services 2025-04-03 N/A
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
CVE-1999-0262 1 Renaud Deraison 1 Faxsurvey 2025-04-03 N/A
Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
CVE-1999-0270 1 Sgi 1 Irix 2025-04-03 N/A
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.