Export limit exceeded: 29990 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (29990 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2005-0936 | 1 Esmi | 1 Paypal Storefront | 2026-04-16 | N/A |
| Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter. | ||||
| CVE-2006-1963 | 1 Pcpin | 1 Pcpin Chat | 2026-04-16 | N/A |
| Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code. | ||||
| CVE-2006-1965 | 1 Aasi Media | 1 Net Clubs Pro | 2026-04-16 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi. | ||||
| CVE-2002-0479 | 1 Gravity Storm Software | 1 Service Pack Manager 2000 | 2026-04-16 | N/A |
| Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share. | ||||
| CVE-2006-1966 | 1 Fortinet | 1 Fortinet28 | 2026-04-16 | N/A |
| An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature is triggering a RST. | ||||
| CVE-2002-0481 | 1 Microsoft | 1 Outlook | 2026-04-16 | N/A |
| An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function. | ||||
| CVE-1999-0243 | 2026-04-16 | N/A | ||
| Linux cfingerd could be exploited to gain root access. | ||||
| CVE-2006-2029 | 1 Simplog | 1 Simplog | 2026-04-16 | N/A |
| Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php. | ||||
| CVE-1999-0276 | 1 Hughes | 1 Msql | 2026-04-16 | N/A |
| mSQL v2.0.1 and below allows remote execution through a buffer overflow. | ||||
| CVE-2002-1933 | 1 Microsoft | 1 Windows 2000 Terminal Services | 2026-04-16 | N/A |
| The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window. | ||||
| CVE-1999-0286 | 2026-04-16 | N/A | ||
| In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. | ||||
| CVE-2002-0518 | 1 Freebsd | 1 Freebsd | 2026-04-16 | N/A |
| The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (2) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart. | ||||
| CVE-2006-2036 | 1 Iopus | 1 Secure Email Attachments | 2026-04-16 | N/A |
| iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring. | ||||
| CVE-1999-0291 | 1 Qbik | 1 Wingate | 2026-04-16 | N/A |
| The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication. | ||||
| CVE-2006-2037 | 1 Thwboard | 1 Thwboard | 2026-04-16 | N/A |
| Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter. | ||||
| CVE-1999-0354 | 1 Microsoft | 2 Internet Explorer, Word | 2026-04-16 | N/A |
| Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. | ||||
| CVE-1999-0356 | 2026-04-16 | N/A | ||
| ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book. | ||||
| CVE-1999-0357 | 1 Microsoft | 1 Windows 98 | 2026-04-16 | N/A |
| Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. | ||||
| CVE-2002-0523 | 1 Asp-nuke | 1 Asp-nuke | 2026-04-16 | N/A |
| ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie. | ||||
| CVE-2006-2050 | 1 Dcscripts | 1 Dcforumlite | 2026-04-16 | N/A |
| SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter. | ||||