Vulnerabilities (CVE)

Total 250881 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0046 1 Celestial Software 1 Absolutetelnet 2023-12-10 4.6 MEDIUM N/A
AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
CVE-2004-0122 1 Microsoft 1 Msn Messenger 2023-12-10 5.0 MEDIUM N/A
Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.
CVE-2003-0500 1 Proftpd Project 1 Proftpd 2023-12-10 10.0 HIGH N/A
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
CVE-2002-1358 7 Cisco, Fissh, Intersoft and 4 more 7 Ios, Ssh Client, Securenetterm and 4 more 2023-12-10 10.0 HIGH N/A
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
CVE-1999-0874 1 Microsoft 3 Internet Information Server, Windows 2000, Windows Nt 2023-12-10 10.0 HIGH N/A
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
CVE-2002-0132 1 Chinput 1 Chinput 2023-12-10 7.2 HIGH N/A
Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.
CVE-2002-1029 1 Worldspan 1 Res Manager 2023-12-10 5.0 MEDIUM N/A
Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 17990.
CVE-2004-1884 2 Ipswitch, Progress 3 Ws Ftp Pro, Ws Ftp Server, Ws Ftp Server 2023-12-10 7.5 HIGH N/A
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
CVE-2002-1182 1 Microsoft 1 Internet Information Services 2023-12-10 5.0 MEDIUM N/A
IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.
CVE-2003-1071 1 Sun 2 Solaris, Sunos 2023-12-10 2.1 LOW N/A
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
CVE-2002-2200 1 Benjamin Lefevre 1 Dobermann Forum 2023-12-10 7.5 HIGH N/A
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.
CVE-2003-1239 1 Wihphoto 1 Wihphoto 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
CVE-2000-0033 1 Trend Micro 1 Interscan Viruswall 2023-12-10 5.0 MEDIUM N/A
InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.
CVE-2001-0465 1 Intuit 1 Turbo Tax 2023-12-10 4.6 MEDIUM N/A
TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.
CVE-2001-1066 1 Sun 1 Solaris 2023-12-10 2.1 LOW N/A
ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.
CVE-2001-0440 3 Conectiva, Licq, Mandrakesoft 3 Linux, Licq, Mandrake Linux 2023-12-10 7.5 HIGH N/A
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
CVE-2002-1455 1 Omnicron 1 Omnihttpd 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
CVE-2003-0758 1 Ibm 1 Db2 Universal Database 2023-12-10 7.2 HIGH N/A
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.
CVE-2001-0754 1 Cisco 1 Cbos 2023-12-10 5.0 MEDIUM N/A
Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets.
CVE-2002-0591 1 Aol 1 Instant Messenger 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.