Export limit exceeded: 358831 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (358831 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2005-4864 | 1 Ibm | 1 Db2 Universal Database | 2026-04-16 | N/A |
| Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable. | ||||
| CVE-1999-0923 | 1 Allaire | 1 Coldfusion Server | 2026-04-16 | N/A |
| Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls. | ||||
| CVE-2006-4068 | 1 Pswd.js | 1 Pswd.js | 2026-04-16 | N/A |
| The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher. | ||||
| CVE-1999-0924 | 1 Allaire | 1 Coldfusion Server | 2026-04-16 | N/A |
| The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service. | ||||
| CVE-1999-0926 | 1 Apache | 1 Http Server | 2026-04-16 | N/A |
| Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. | ||||
| CVE-2005-4869 | 1 Ibm | 1 Db2 | 2026-04-16 | N/A |
| The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference. | ||||
| CVE-2005-4871 | 1 Ibm | 1 Db2 | 2026-04-16 | N/A |
| Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile. | ||||
| CVE-1999-0941 | 1 Mutt | 1 Mutt | 2026-04-16 | N/A |
| Mutt mail client allows a remote attacker to execute commands via shell metacharacters. | ||||
| CVE-2006-4069 | 1 Ozjournals | 1 Ozjournals | 2026-04-16 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action. | ||||
| CVE-2005-4872 | 2 Pcre, Redhat | 2 Pcre, Enterprise Linux | 2026-04-16 | N/A |
| Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of named subpatterns, which triggers a buffer overflow. NOTE: this issue was originally subsumed by CVE-2006-7224, but that CVE has been REJECTED and split. | ||||
| CVE-2006-4070 | 1 Imendio Planner | 1 Imendio Planner | 2026-04-16 | N/A |
| Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename. | ||||
| CVE-1999-0953 | 1 Matt Wright | 1 Wwwboard | 2026-04-16 | N/A |
| WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. | ||||
| CVE-2005-4873 | 1 Cups | 1 Cups | 2026-04-16 | N/A |
| Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by the cups_get_dest_options function in phpcups.c. | ||||
| CVE-2005-4853 | 1 Ez | 1 Ez Publish | 2026-04-16 | N/A |
| The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings. | ||||
| CVE-1999-0818 | 1 Sun | 2 Solaris, Sunos | 2026-04-16 | N/A |
| Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | ||||
| CVE-1999-0817 | 1 University Of Kansas | 1 Lynx | 2026-04-16 | N/A |
| Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet. | ||||
| CVE-1999-0816 | 1 Motorola | 1 Motorola Cablerouter | 2026-04-16 | N/A |
| The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024. | ||||
| CVE-1999-0815 | 1 Microsoft | 1 Windows Nt | 2026-04-16 | N/A |
| Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. | ||||
| CVE-1999-0814 | 1 Redhat | 1 Linux | 2026-04-16 | N/A |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. | ||||
| CVE-1999-0812 | 1 Samba | 1 Samba | 2026-04-16 | N/A |
| Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations. | ||||