Search Results (29880 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2005-2861 1 N-stalker 1 N-stealth 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report.
CVE-2005-2869 1 Phpmyadmin 1 Phpmyadmin 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.
CVE-1999-0158 1 Cisco 1 Pix Firewall Software 2025-04-03 N/A
Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
CVE-2005-2879 1 Advansysperu Software 1 Usb Lock Auto-protect 2025-04-03 N/A
Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection.
CVE-2005-2882 1 Phpcommunitycalendar 1 Phpcommunitycalendar 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php, (6) calWeekly.php, (7) calWeeklyP.php, (8) calYearly.php, (9) calYearlyP.php, (10) day.php, or (11) week.php, or (12) CeTi, (13) Contact, (14) Description, (15) ShowAddress parameter to event.php, and other attack vectors.
CVE-2006-1584 1 Juliusz Julas Gonera 1 Warcraft Iii Replay Parser Php 2025-04-03 N/A
Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.
CVE-2005-2884 1 Neocrome 1 Land Down Under 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers to inject arbitrary web script or HTML via the Description field in an event.
CVE-1999-0157 1 Cisco 2 Ios, Pix Firewall Software 2025-04-03 N/A
Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
CVE-1999-0156 1 Washington University 1 Wu-ftpd 2025-04-03 N/A
wu-ftpd FTP daemon allows any user and password combination.
CVE-1999-0155 1 Aladdin Enterprises 1 Ghostscript 2025-04-03 N/A
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
CVE-2005-2917 2 Redhat, Squid 2 Enterprise Linux, Squid 2025-04-03 N/A
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
CVE-1999-0152 1 Data General 1 Dg Ux 2025-04-03 N/A
The DG/UX finger daemon allows remote command execution through shell metacharacters.
CVE-1999-0141 1 Netscape 1 Navigator 2025-04-03 N/A
Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.
CVE-1999-0261 2025-04-03 N/A
Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.
CVE-1999-0145 1 Eric Allman 1 Sendmail 2025-04-03 N/A
Sendmail WIZ command enabled, allowing root access.
CVE-1999-0271 2025-04-03 N/A
Progressive Networks Real Video server (pnserver) can be crashed remotely.
CVE-1999-0274 1 Microsoft 1 Windows Nt 2025-04-03 N/A
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
CVE-1999-0291 1 Qbik 1 Wingate 2025-04-03 N/A
The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.
CVE-1999-0292 1 Microsoft 1 Windows Nt 2025-04-03 N/A
Denial of service through Winpopup using large user names.
CVE-1999-0149 1 Sgi 1 Irix 2025-04-03 N/A
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.