Vulnerabilities (CVE)

Total 90413 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0681 1 Goahead Software 1 Goahead Webserver 2023-12-10 7.5 HIGH N/A
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.
CVE-2000-0717 1 Goodtech 2 Ftp Server 95 98, Ftp Server Nt 2000 2023-12-10 5.0 MEDIUM N/A
GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.
CVE-2000-0440 2 Freebsd, Netbsd 2 Freebsd, Netbsd 2023-12-10 5.0 MEDIUM N/A
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
CVE-1999-0167 1 Sun 1 Sunos 2023-12-10 4.6 MEDIUM N/A
In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
CVE-1999-1270 1 Kde 1 Kde 2023-12-10 4.6 MEDIUM N/A
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
CVE-2002-0996 1 Novell 2 Netmail, Netmail Xe 2023-12-10 7.5 HIGH N/A
Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.
CVE-2003-1036 1 Sap 1 Internet Transaction Server 2023-12-10 7.5 HIGH N/A
Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.
CVE-1999-0290 1 Qbik 1 Wingate 2023-12-10 5.0 MEDIUM N/A
The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.
CVE-2000-1088 1 Microsoft 2 Data Engine, Sql Server 2023-12-10 4.6 MEDIUM N/A
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
CVE-2001-0212 1 His 1 Auktion 2023-12-10 7.5 HIGH N/A
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
CVE-2002-0915 1 Harald Hoyer 2 Autorun, Xandros Desktop Os 2023-12-10 2.1 LOW N/A
autorun in Xandros based Linux distributions allows local users to read the first line of arbitrary files via the -c parameter, which causes autorun to print the first line of the file.
CVE-1999-1093 1 Microsoft 1 Internet Explorer 2023-12-10 5.1 MEDIUM N/A
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
CVE-1999-0739 1 Microsoft 1 Internet Information Server 2023-12-10 5.0 MEDIUM N/A
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-2000-0249 1 Ibm 1 Aix 2023-12-10 7.2 HIGH N/A
The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.
CVE-2000-1003 1 Microsoft 3 Windows 95, Windows 98, Windows 98se 2023-12-10 2.6 LOW N/A
NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.
CVE-1999-0386 1 Microsoft 2 Frontpage, Personal Web Server 2023-12-10 5.0 MEDIUM N/A
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
CVE-2003-1370 1 Nuked-klan 1 Nuked-klan 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.
CVE-1999-0213 1 Sun 2 Solaris, Sunos 2023-12-10 10.0 HIGH N/A
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
CVE-2002-1112 1 Mantis 1 Mantis 2023-12-10 5.0 MEDIUM N/A
Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.
CVE-2004-1825 1 Mambo 1 Mambo Open Source 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.