Export limit exceeded: 404065 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404065 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-1999-0204 | 1 Eric Allman | 1 Sendmail | 2026-04-16 | N/A |
| Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | ||||
| CVE-1999-0170 | 1 Digital | 1 Ultrix | 2026-04-16 | N/A |
| Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. | ||||
| CVE-1999-0171 | 1 Linux | 1 Linux Kernel | 2026-04-16 | N/A |
| Denial of service in syslog by sending it a large number of superfluous messages. | ||||
| CVE-1999-0182 | 1 Samba | 1 Samba | 2026-04-16 | N/A |
| Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password. | ||||
| CVE-1999-0190 | 1 Sun | 2 Solaris, Sunos | 2026-04-16 | N/A |
| Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. | ||||
| CVE-2004-0462 | 2026-04-16 | N/A | ||
| The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server. | ||||
| CVE-1999-0222 | 1 Cisco | 1 Router | 2026-04-16 | N/A |
| Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. | ||||
| CVE-1999-0223 | 1 Sun | 1 Sunos | 2026-04-16 | N/A |
| Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. | ||||
| CVE-1999-0233 | 1 Microsoft | 1 Internet Information Services | 2026-04-16 | N/A |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. | ||||
| CVE-1999-0238 | 1 Php | 1 Php | 2026-04-16 | N/A |
| php.cgi allows attackers to read any file on the system. | ||||
| CVE-2003-1309 | 1 Zonelabs | 1 Zonealarm | 2026-04-16 | N/A |
| The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack"). | ||||
| CVE-1999-0244 | 1 Livingston | 1 Radius | 2026-04-16 | N/A |
| Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. | ||||
| CVE-1999-0250 | 1 Dan Bernstein | 1 Qmail | 2026-04-16 | N/A |
| Denial of service in Qmail through long SMTP commands. | ||||
| CVE-2005-3618 | 1 Vmware | 1 Esx | 2026-04-16 | N/A |
| Cross-site request forgery (CSRF) vulnerability in the management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 allows allows remote attackers to perform unauthorized actions as the administrator via URLs, as demonstrated using the setUsr operation to change a password. NOTE: this issue can be leveraged with CVE-2005-3619 to automatically perform the attacks. | ||||
| CVE-2006-3120 | 1 Brian Wotring | 1 Osiris | 2026-04-16 | N/A |
| Format string vulnerability in Brian Wotring Osiris before 4.2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified attack vectors related to the logging functions. | ||||
| CVE-2006-3929 | 1 Zyxel | 1 Prestige 660h-61 | 2026-04-16 | N/A |
| Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter. | ||||
| CVE-1999-0321 | 1 Sun | 1 Solaris | 2026-04-16 | N/A |
| Buffer overflow in Solaris kcms_configure command allows local users to gain root access. | ||||
| CVE-2006-3934 | 1 Alkacon | 1 Opencms | 2026-04-16 | N/A |
| Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter. | ||||
| CVE-2006-3935 | 1 Alkacon | 1 Opencms | 2026-04-16 | N/A |
| system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add webusers (/accounts/webusers/new), (4) upload database import and export files (/database/importhttp), (5) upload arbitrary program modules (/modules/modules_import), and (6) read the log file (/workplace/logfileview) by setting the appropriate value for the path parameter in a direct request to admin-main.jsp. | ||||
| CVE-2006-3936 | 1 Alkacon | 1 Opencms | 2026-04-16 | N/A |
| system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp. | ||||