Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,944 CVEs tagged with CWE-201,639 Critical, 5,065 High, 5,714 Medium, 522 Low, 4 Unrated.

CVE-2006-0321

Published Jan 24, 2006

fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0340

Published Jan 21, 2006

Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote atta…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0203

Published Jan 13, 2006

membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4846

Published Dec 31, 2005

Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3946

Published Dec 1, 2005

Opera 8.50 allows remote attackers to cause a denial of service (crash) via a Java applet with a large string argument to the removeMember JNI method for the com.opera.JSObject cl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3678

Published Nov 18, 2005

Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3591

Published Nov 16, 2005

Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3467

Published Nov 2, 2005

Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3330

Published Oct 27, 2005

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary comm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3183

Published Oct 12, 2005

The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byterang…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3055

Published Sep 26, 2005

Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and te…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2806

Published Sep 6, 2005

client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2405

Published Aug 1, 2005

Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2177

Published Jul 11, 2005

Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon ha…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1787

Published May 27, 2005

setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1795

Published May 27, 2005

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1682

Published May 20, 2005

JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeader…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1628

Published May 17, 2005

apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1330

Published May 4, 2005

AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, lea…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1398

Published May 3, 2005

phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0200

Published May 2, 2005

TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP script…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 12,826-12,850 of 12,944 CVEsPage 514 of 518