Show filters
72 Total Results
Displaying 61-70 of 72
Sort by:
Attacker Value
Unknown
CVE-2006-5950
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
0
Attacker Value
Unknown
CVE-2006-3210
Disclosure Date: June 24, 2006 (last updated October 04, 2023)
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2006-0734
Disclosure Date: February 16, 2006 (last updated February 22, 2025)
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.
0
Attacker Value
Unknown
CVE-2006-0085
Disclosure Date: January 05, 2006 (last updated February 22, 2025)
SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.
0
Attacker Value
Unknown
CVE-2004-0724
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
0
Attacker Value
Unknown
CVE-2003-1325
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.
0
Attacker Value
Unknown
CVE-2002-0964
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out.
0
Attacker Value
Unknown
CVE-2001-0964
Disclosure Date: September 20, 2001 (last updated February 22, 2025)
Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.
0
Attacker Value
Unknown
CVE-2001-0358
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.
0
Attacker Value
Unknown
CVE-2001-0359
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.
0