Search Results (29990 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-1999-0637 2026-04-16 N/A
The systat service is running.
CVE-1999-0640 2026-04-16 N/A
The Gopher service is running.
CVE-2005-0836 1 Sun 1 J2se 2026-04-16 N/A
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.
CVE-1999-0651 2026-04-16 N/A
The rsh/rlogin service is running.
CVE-1999-0657 2026-04-16 N/A
WinGate is being used.
CVE-1999-0664 2026-04-16 N/A
An application-critical Windows NT registry key has inappropriate permissions.
CVE-2005-0842 1 Kayako 1 Esupport 2026-04-16 N/A
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.
CVE-2005-0843 1 Phorum 1 Phorum 2026-04-16 N/A
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.
CVE-1999-0676 1 Sun 2 Solaris, Sunos 2026-04-16 N/A
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-2005-4174 1 Efiction Project 1 Efiction 2026-04-16 N/A
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.
CVE-2005-4175 1 Insyde 1 Insyde Bios 2026-04-16 N/A
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
CVE-2005-4189 1 Horde 1 Kronolith H3 2026-04-16 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith H3 before 2.0.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Calendar name field when creating calendars, (2) event title field when deleting events, the (3) Category and (4) Location search fields, and the (5) attendees email address fields when editing event attendees, and possibly other vectors.
CVE-2005-4272 1 Ibm 1 Aix 2026-04-16 N/A
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
CVE-1999-0690 2 Cde, Hp 2 Cde, Hp-ux 2026-04-16 N/A
HP CDE program includes the current directory in root's PATH variable.
CVE-1999-0692 2 Cray, Sgi 2 Unicos, Irix 2026-04-16 N/A
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
CVE-1999-0694 1 Ibm 1 Aix 2026-04-16 N/A
Denial of service in AIX ptrace system call allows local users to crash the system.
CVE-2005-0852 1 Microsoft 1 Windows Xp 2026-04-16 N/A
Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
CVE-2005-4277 1 Toenda Software Development 1 Toendacms 2026-04-16 N/A
Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-1999-0697 1 Sco 1 Openserver 2026-04-16 N/A
SCO Doctor allows local users to gain root privileges through a Tools option.
CVE-1999-0698 2026-04-16 N/A
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.