Export limit exceeded: 372208 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372208 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372208 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2006-0652 | 1 Whmcompletesolution | 1 Whmcompletesolution | 2026-04-16 | N/A |
| WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability. | ||||
| CVE-1999-0366 | 1 Microsoft | 1 Windows Nt | 2026-04-16 | N/A |
| In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | ||||
| CVE-2006-0650 | 1 Cpaint | 1 Cpaint | 2026-04-16 | N/A |
| Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag. | ||||
| CVE-2004-2212 | 1 Alivesites | 1 Alivesites Forum | 2026-04-16 | N/A |
| SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter. | ||||
| CVE-2005-4713 | 1 Pam Mysql | 1 Pam Mysql | 2026-04-16 | N/A |
| Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP address argument to an sprintf call. | ||||
| CVE-2006-0598 | 1 Stefan Ritt | 1 Elog Web Logbook | 2026-04-16 | N/A |
| Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file. | ||||
| CVE-2003-0826 | 1 Gnu | 1 Lsh | 2026-04-16 | N/A |
| lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack. | ||||
| CVE-2003-0697 | 1 Ibm | 1 Aix | 2026-04-16 | N/A |
| Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges. | ||||
| CVE-1999-0328 | 1 Sgi | 1 Irix | 2026-04-16 | N/A |
| SGI permissions program allows local users to gain root privileges. | ||||
| CVE-1999-0326 | 1 Hp | 1 Hp-ux | 2026-04-16 | N/A |
| Vulnerability in HP-UX mediainit program. | ||||
| CVE-1999-0322 | 1 Freebsd | 1 Freebsd | 2026-04-16 | N/A |
| The open() function in FreeBSD allows local attackers to write to arbitrary files. | ||||
| CVE-1999-0316 | 1 Sam Lantinga | 1 Splitvt | 2026-04-16 | N/A |
| Buffer overflow in Linux splitvt command gives root access to local users. | ||||
| CVE-1999-0308 | 1 Hp | 1 Hp-ux | 2026-04-16 | N/A |
| HP-UX gwind program allows users to modify arbitrary files. | ||||
| CVE-1999-0295 | 1 Sun | 2 Solaris, Sunos | 2026-04-16 | N/A |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. | ||||
| CVE-1999-0289 | 2 Apache, Microsoft | 2 Http Server, Windows | 2026-04-16 | N/A |
| The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. | ||||
| CVE-1999-0288 | 1 Microsoft | 1 Windows Nt | 2026-04-16 | N/A |
| The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. | ||||
| CVE-1999-0278 | 1 Microsoft | 2 Internet Information Server, Windows Nt | 2026-04-16 | N/A |
| In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. | ||||
| CVE-1999-0263 | 1 Sun | 1 Sunos | 2026-04-16 | N/A |
| Solaris SUNWadmap can be exploited to obtain root access. | ||||
| CVE-2004-2198 | 1 Duware | 1 Duclassmate | 2026-04-16 | N/A |
| account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page. | ||||
| CVE-2006-1493 | 1 Nikolay Avrionov | 1 Explorer Xp | 2026-04-16 | N/A |
| Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. NOTE: it is possible that this issue is resultant from CVE-2006-1492. | ||||