Severity: CRITICAL

29068 CVEs found

CVE-2004-0772
9.8 CRITICAL

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.

Published: 2004-10-20
Products: 4
Vendors:
debian mit openpkg
CVE-2004-0847
9.8 CRITICAL

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash)...

Published: 2004-11-03
Products: 2
Vendors:
microsoft
CVE-2004-0285
9.8 CRITICAL

PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMV...

Published: 2004-11-23
Products: 13
Vendors:
allmylinks_project allmyguests_project allmyvisitors_project
CVE-2004-2154
9.8 CRITICAL

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are ...

Published: 2004-12-31
Products: 3
Vendors:
canonical apple
CVE-2004-2214
9.8 CRITICAL

Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.

Published: 2004-12-31
Products: 1
Vendors:
mbedthis
CVE-2005-0102
9.8 CRITICAL

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte ...

Published: 2005-01-24
Products: 2
Vendors:
debian gnome
CVE-2005-0408
9.8 CRITICAL

CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating th...

Published: 2005-02-14
Products: 1
Vendors:
citrusdb
CVE-2005-0496
9.8 CRITICAL

Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.

Published: 2005-02-21
Products: 1
Vendors:
arkeia
CVE-2005-1141
9.8 CRITICAL

Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, whi...

Published: 2005-04-15
Products: 1
Vendors:
optical_character_recognition_project
CVE-2005-0199
9.8 CRITICAL

Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a ...

Published: 2005-05-02
Products: 1
Vendors:
barton
CVE-2005-0269
9.8 CRITICAL

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that incl...

Published: 2005-05-02
Products: 1
Vendors:
sir
CVE-2005-1513
9.8 CRITICAL

Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly ...

Published: 2005-05-11
Products: 5
Vendors:
debian canonical qmail_project
CVE-2005-1744
9.8 CRITICAL

BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without hav...

Published: 2005-05-24
Products: 1
Vendors:
bea
CVE-2005-1689
9.8 CRITICAL

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

Published: 2005-07-18
Products: 5
Vendors:
debian mit apple
CVE-2005-2103
9.8 CRITICAL

Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a l...

Published: 2005-08-16
Products: 1
Vendors:
gaim_project
CVE-2005-2773
9.8 CRITICAL

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3)...

Published: 2005-09-02
Products: 1
Vendors:
hp
CVE-2005-3120
9.8 CRITICAL

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lyn...

Published: 2005-10-17
Products: 3
Vendors:
debian invisible-island
CVE-2005-3435
9.8 CRITICAL

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and sp...

Published: 2005-11-02
Products: 1
Vendors:
archilles
CVE-2007-0681
9.8 CRITICAL

profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, vi...

Published: 2007-02-03
Products: 1
Vendors:
extcalendar_project
CVE-2006-7079
9.8 CRITICAL

Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute ...

Published: 2007-03-02
Products: 1
Vendors:
exv2