Search Results (390953 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2006-3682 1 Awstats 1 Awstats 2026-04-16 N/A
awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.
CVE-2006-3689 1 Codeworks 1 Gnomedia Subberz 2026-04-16 N/A
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed.
CVE-2006-3692 1 Silentweb 1 Listmessenger 2026-04-16 N/A
PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker's post-disclosure analysis
CVE-2004-2676 1 Webroot Software 1 Spy Sweeper Enterprise 2026-04-16 N/A
The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges.
CVE-2005-4729 1 Vbzoom 1 Vbzoom 2026-04-16 N/A
SQL injection vulnerability in show.php in VBZooM Forum allows remote attackers to execute arbitrary SQL commands via the SubjectID parameter.
CVE-2006-1140 1 Redblog 1 Redblog 2026-04-16 N/A
SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2006-1144 1 David Ravenscroft 1 Hithost 2026-04-16 N/A
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.
CVE-2006-1152 1 M Phorum 1 M Phorum 2026-04-16 N/A
PHP remote file inclusion vulnerability in index.php in M-Phorum 0.2 allows remote attackers to include arbitrary files via the go parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-1999-0008 2 Hp, Sun 3 Hp-ux, Solaris, Sunos 2026-04-16 N/A
Buffer overflow in NIS+, in Sun's rpc.nisd program.
CVE-1999-0088 1 Ibm 1 Aix 2026-04-16 N/A
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
CVE-1999-0120 1 Sun 1 Sunos 2026-04-16 N/A
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
CVE-1999-0137 1 Fred N. Van Kempen 1 Dip 2026-04-16 N/A
The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
CVE-1999-0152 1 Data General 1 Dg Ux 2026-04-16 N/A
The DG/UX finger daemon allows remote command execution through shell metacharacters.
CVE-1999-0164 1 Sun 1 Sunos 2026-04-16 N/A
A race condition in the Solaris ps command allows an attacker to overwrite critical files.
CVE-1999-0169 1 Sun 1 Nfs 2026-04-16 N/A
NFS allows attackers to read and write any file on the system by specifying a false UID.
CVE-1999-0182 1 Samba 1 Samba 2026-04-16 N/A
Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
CVE-1999-0195 2 Linux, Sgi 2 Linux Kernel, Irix 2026-04-16 N/A
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
CVE-1999-0204 1 Eric Allman 1 Sendmail 2026-04-16 N/A
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
CVE-1999-0215 1 Sgi 1 Irix 2026-04-16 N/A
Routed allows attackers to append data to files.
CVE-1999-0218 1 Livingston Portmaster 1 Portmaster 2026-04-16 N/A
Livingston portmaster machines could be rebooted via a series of commands.