Vulnerabilities (CVE)

Total 251332 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0178 1 Oreilly 1 Oreilly Website 2023-12-10 7.5 HIGH N/A
Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.
CVE-2002-1993 1 Affordable Web Space Design 1 Affordable Web Space Design Webbbs 2023-12-10 10.0 HIGH N/A
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.
CVE-2003-1473 1 Lgames 1 Ltris 2023-12-10 4.6 MEDIUM N/A
Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.
CVE-2001-1106 1 Sambar 1 Sambar Server 2023-12-10 7.5 HIGH N/A
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
CVE-2000-0704 3 Freewnn, Omron, Wnn 3 Freewnn, Worldview, Wnn4 2023-12-10 10.0 HIGH N/A
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.
CVE-2000-0546 3 Cygnus Network Security Project, Kerbnet Project, Mit 4 Cygnus Network Security, Kerbnet, Kerberos and 1 more 2023-12-10 5.0 MEDIUM N/A
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
CVE-2004-1499 1 Webhost Automation 1 Helm Control Panel 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
CVE-2001-1053 1 Adcycle 1 Adcycle 2023-12-10 10.0 HIGH N/A
AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.
CVE-2002-0245 1 Lotus 1 Domino 2023-12-10 7.5 HIGH N/A
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.
CVE-2004-0540 1 Microsoft 1 Windows 2000 2023-12-10 10.0 HIGH N/A
Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
CVE-2000-1190 1 Jon Atkins 1 Imwheel 2023-12-10 2.1 LOW N/A
imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.
CVE-2004-1748 1 Sysinternals 1 Regmon 2023-12-10 2.1 LOW N/A
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.
CVE-2002-1091 3 Mozilla, Netscape, Opera Software 3 Mozilla, Navigator, Opera Web Browser 2023-12-10 7.5 HIGH N/A
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
CVE-2002-0060 1 Linux 1 Linux Kernel 2023-12-10 7.5 HIGH N/A
IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictions.
CVE-2000-1207 1 Redhat 1 Linux 2023-12-10 7.2 HIGH N/A
userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).
CVE-1999-0225 1 Microsoft 1 Windows Nt 2023-12-10 5.0 MEDIUM N/A
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
CVE-2001-0348 1 Microsoft 1 Windows 2000 2023-12-10 5.0 MEDIUM N/A
Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
CVE-2002-1434 1 Kerio 1 Kerio Mailserver 2023-12-10 6.8 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
CVE-2003-0789 1 Apache 1 Http Server 2023-12-10 10.0 HIGH N/A
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
CVE-2000-0875 1 Texas Imperial Software 2 Wftpd, Wftpd Pro 2023-12-10 5.0 MEDIUM N/A
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.