Export limit exceeded: 344983 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 344983 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (344983 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-1999-0923 | 1 Allaire | 1 Coldfusion Server | 2026-04-16 | N/A |
| Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. | ||||
| CVE-1999-0927 | 1 Gordano | 1 Ntmail | 2026-04-16 | N/A |
| NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. | ||||
| CVE-1999-0928 | 1 Smartdesk | 1 Websuite | 2026-04-16 | N/A |
| Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. | ||||
| CVE-1999-0930 | 1 Matt Wright | 1 Wwwboard | 2026-04-16 | N/A |
| wwwboard allows a remote attacker to delete message board articles via a malformed argument. | ||||
| CVE-1999-0931 | 1 Mediahouse Software | 1 Statistics Server | 2026-04-16 | N/A |
| Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. | ||||
| CVE-1999-0932 | 1 Mediahouse Software | 1 Statistics Server | 2026-04-16 | N/A |
| Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file. | ||||
| CVE-1999-0933 | 1 Teamshare | 1 Teamtrack | 2026-04-16 | N/A |
| TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | ||||
| CVE-1999-0934 | 2026-04-16 | N/A | ||
| classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters. | ||||
| CVE-1999-0937 | 2026-04-16 | N/A | ||
| BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. | ||||
| CVE-1999-0938 | 1 University College London | 1 Sdr | 2026-04-16 | N/A |
| MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages. | ||||
| CVE-1999-0939 | 1 Debian | 1 Debian Linux | 2026-04-16 | N/A |
| Denial of service in Debian IRC Epic/epic4 client via a long string. | ||||
| CVE-2000-0546 | 3 Cygnus Network Security Project, Kerbnet Project, Mit | 4 Cygnus Network Security, Kerbnet, Kerberos and 1 more | 2026-04-16 | N/A |
| Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function. | ||||
| CVE-1999-0940 | 1 Mutt | 1 Mutt Mail Client | 2026-04-16 | N/A |
| Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages. | ||||
| CVE-1999-0941 | 1 Mutt | 1 Mutt | 2026-04-16 | N/A |
| Mutt mail client allows a remote attacker to execute commands via shell metacharacters. | ||||
| CVE-2006-3608 | 1 Flatnuke | 1 Flatnuke | 2026-04-16 | N/A |
| The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file. | ||||
| CVE-2006-3584 | 1 Jetbox | 1 Jetbox Cms | 2026-04-16 | N/A |
| Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables. | ||||
| CVE-2006-3569 | 1 Ibm | 1 Network Appliance Data Ontap | 2026-04-16 | N/A |
| Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other products, allows unauthorized users to gain access to privileged commands via unknown vectors, probably related to incorrect capabilities with the audit role. | ||||
| CVE-2006-3539 | 1 Dkscript | 1 Dragons Kingdom Script | 2026-04-16 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com Dragon's Kingdom Script 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) Subject and (2) Message fields in a do=write (aka Send Mail Message) action in gamemail.php; the (3) Gender, (4) Country/Location, (5) MSN Messenger, (6) AOL Instant Messenger, (7) Yahoo Instant Messenger, and (8) ICQ fields in a do=onlinechar (aka Edit your Profile) action in index.php, as accessed by dk.php; a javascript URI in the SRC attribute of an IMG element in the (9) Title and (10) Message fields in a do=new (aka Create Thread) action in general.php; and a javascript URI in the SRC attribute of an IMG element in unspecified fields in (11) other Forum posts and (12) Forum replies. | ||||
| CVE-2006-3536 | 1 Ej3 | 1 Topo | 2026-04-16 | N/A |
| Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbitrary PHP code via parameters such as (1) descripcion and (2) pais, which are stored directly in a PHP script. NOTE: the provenance of this information is unknown; the details are obtained solely from third party reports. | ||||
| CVE-2006-3484 | 1 Adaptive Technology Resource Centre | 1 Atutor | 2026-04-16 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php. | ||||