Show filters
545 Total Results
Displaying 481-490 of 545
Sort by:
Attacker Value
Unknown
CVE-2006-1840
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.
0
Attacker Value
Unknown
CVE-2006-1656
Disclosure Date: April 06, 2006 (last updated February 22, 2025)
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
0
Attacker Value
Unknown
CVE-2006-0816
Disclosure Date: March 24, 2006 (last updated February 22, 2025)
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
0
Attacker Value
Unknown
CVE-2006-0822
Disclosure Date: February 21, 2006 (last updated February 22, 2025)
Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a "ghost game" to be left on the server.
0
Attacker Value
Unknown
CVE-2006-0535
Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-4418
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
0
Attacker Value
Unknown
CVE-2005-4237
Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.
0
Attacker Value
Unknown
CVE-2005-3475
Disclosure Date: November 03, 2005 (last updated February 22, 2025)
Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests.
0
Attacker Value
Unknown
CVE-2005-2981
Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
0
Attacker Value
Unknown
CVE-2005-2634
Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Buffer overflow in the Log-SCR function in the "Log to Screen" feature in WinFtp Server 1.6.8 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long request.
0