Export limit exceeded: 391127 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (29996 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2001-1173 1 Masqmail 1 Masqmail 2026-04-16 N/A
Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.
CVE-1999-0168 1 Sun 1 Sunos 2026-04-16 N/A
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
CVE-1999-1083 1 T. Hauck 1 Jana Web Server 2026-04-16 N/A
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.
CVE-1999-0174 1 Netscape 1 Communicator 2026-04-16 N/A
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-1091 2 Rtin, Tin 2 Rtin, Tin 2026-04-16 N/A
UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.
CVE-1999-0183 2 Linux, Tftp 2 Linux Kernel, Tftp 2026-04-16 N/A
Linux implementations of TFTP would allow access to files outside the restricted directory.
CVE-1999-0184 1 Isc 1 Bind 2026-04-16 N/A
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
CVE-1999-0185 1 Sun 2 Solaris, Sunos 2026-04-16 N/A
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
CVE-1999-0188 1 Sun 2 Solaris, Sunos 2026-04-16 N/A
The passwd command in Solaris can be subjected to a denial of service.
CVE-1999-0189 1 Sun 2 Solaris, Sunos 2026-04-16 N/A
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
CVE-2004-1711 1 Moodle 1 Moodle 2026-04-16 N/A
Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
CVE-1999-0191 1 Microsoft 1 Internet Information Server 2026-04-16 N/A
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-1093 1 Microsoft 1 Internet Explorer 2026-04-16 N/A
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
CVE-1999-0192 2 Redhat, Slackware 2 Linux, Slackware Linux 2026-04-16 N/A
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CVE-1999-0193 1 Ascend 1 Cascadeview Ux 2026-04-16 N/A
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
CVE-1999-0196 1 Webgais Development Team 1 Webgais 2026-04-16 N/A
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
CVE-2005-4646 1 Pearlinger 1 Pearl Forums 2026-04-16 N/A
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-1999-0201 1 Ftp 1 Ftp 2026-04-16 N/A
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
CVE-1999-0202 1 University Of Washington 1 Wu-ftpd 2026-04-16 N/A
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
CVE-2005-4649 1 Advanced Guestbook 1 Advanced Guestbook 2026-04-16 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.