{"resultsPerPage":10,"startIndex":0,"totalResults":1064,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-21T02:11:03.111","vulnerabilities":[{"cve":{"id":"CVE-1999-1356","sourceIdentifier":"cve@mitre.org","published":"1999-09-02T04:00:00.000","lastModified":"2026-06-16T21:50:15.973","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:compaq:smartstart:*:*:*:*:*:*:*:*","versionEndIncluding":"4.50","matchCriteriaId":"ED239855-5A0A-4C76-806A-DEDEC9819A74"}]}]}],"references":[{"url":"http://marc.info/?l=bugtraq&m=93646669500991&w=2","source":"cve@mitre.org"},{"url":"http://marc.info/?l=ntbugtraq&m=93637792706047&w=2","source":"cve@mitre.org"},{"url":"http://marc.info/?l=ntbugtraq&m=93759822830815&w=2","source":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/7763.php","source":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=93646669500991&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=ntbugtraq&m=93637792706047&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=ntbugtraq&m=93759822830815&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.iss.net/security_center/static/7763.php","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2002-0505","sourceIdentifier":"cve@mitre.org","published":"2002-08-12T04:00:00.000","lastModified":"2026-06-16T21:57:34.440","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords."},{"lang":"es","value":"Fuga de memoria en la autenticación Call Telephony Integration (CTI) Framework en Cisco CallManager 3.0 y 3.1 anteriores a 3.1(3) permite a atacantes remotos causar una denegación de servicio (caída y recarga) mediante una serie de fallos de autenticación, por ejemplo mediante contraseñas incorrectas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:call_manager:3.0:*:*:*:*:*:*:*","matchCriteriaId":"C08E2D6A-1B4C-4BDA-8FF7-8D61A393460E"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:call_manager:3.1:*:*:*:*:*:*:*","matchCriteriaId":"AF7E0B10-11E0-44B7-A450-AA5AB058C6C5"}]}]}],"references":[{"url":"http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtml","source":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/8655.php","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/4370","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtml","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.iss.net/security_center/static/8655.php","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/4370","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2002-1321","sourceIdentifier":"cve@mitre.org","published":"2002-12-11T05:00:00.000","lastModified":"2026-06-16T21:59:06.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain \"Now Playing\" options on a downloaded file with a long filename."},{"lang":"es","value":"Mültiples desbordamientos de búfer en RealOne y RealPlayer permite a atacantes remotos ejecutar código arbitrario mediante \r\n\r\nun fichero de Lenguaje de Integración Multimedia Sincronizada (SMIL) con un parámetro largo.\r\nun nombre de fichero largo en una petición rtsp://, por ejemplo un fichero. m3u, o\r\nCiertas opciones \"Now Playing\" (Reproduciendo Ahora) en un fichero descargado con un nombre de fichero largo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*","matchCriteriaId":"CF6535A6-6647-4E60-B5AA-24DFC06360AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:*:g2:*:*:*:*:*:*","matchCriteriaId":"F443B415-782D-4059-931E-222968D5CC8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:6.0:*:win32:*:*:*:*:*","matchCriteriaId":"65124AAD-0F80-4FBB-8A29-420C445E889C"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:7.0:*:win32:*:*:*:*:*","matchCriteriaId":"2F5492A8-E1B6-4ADF-B057-125ECD8B7FE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:8.0:*:win32:*:*:*:*:*","matchCriteriaId":"003D7E29-9970-4984-9756-C070E15B7979"}]}]}],"references":[{"url":"http://marc.info/?l=bugtraq&m=103808645120764&w=2","source":"cve@mitre.org"},{"url":"http://service.real.com/help/faq/security/bufferoverrun_player.html","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/6227","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/6229","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10677","source":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=103808645120764&w=2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://service.real.com/help/faq/security/bufferoverrun_player.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/6227","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/6229","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/10677","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2002-1794","sourceIdentifier":"cve@mitre.org","published":"2002-12-31T05:00:00.000","lastModified":"2026-06-16T21:59:59.580","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:ldap-ux_integration:b.02.00:*:*:*:*:*:*:*","matchCriteriaId":"22A26F71-2F31-4F3B-B170-A59AD8B199D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:ldap-ux_integration:b.03.00:*:*:*:*:*:*:*","matchCriteriaId":"3E530E6E-AF1C-438B-B81A-953F471BC3ED"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*","matchCriteriaId":"771931F7-9180-4EBD-8627-E1CF17D24647"},{"vulnerable":true,"criteria":"cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*","matchCriteriaId":"EDD9BE2B-7255-4FC1-B452-E8370632B03F"}]}]}],"references":[{"url":"http://online.securityfocus.com/advisories/4512","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://www.ciac.org/ciac/bulletins/n-006.shtml","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://www.iss.net/security_center/static/10266.php","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/5839","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5593","source":"cve@mitre.org"},{"url":"http://online.securityfocus.com/advisories/4512","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.ciac.org/ciac/bulletins/n-006.shtml","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://www.iss.net/security_center/static/10266.php","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://www.securityfocus.com/bid/5839","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5593","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2003-0733","sourceIdentifier":"cve@mitre.org","published":"2003-10-20T04:00:00.000","lastModified":"2026-06-16T22:02:43.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console application."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bea:liquid_data:1.1:*:*:*:*:*:*:*","matchCriteriaId":"33A4F5FB-69A0-49D0-81D1-D831C3E7BE1F"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_integration:2.0:*:*:*:*:*:*:*","matchCriteriaId":"075BB751-A3EF-40DB-8D9C-9F7FB49061C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_integration:7.0:*:*:*:*:*:*:*","matchCriteriaId":"0AB49671-9D20-44B1-93DE-261AD900679E"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:5.1:*:*:*:*:*:*:*","matchCriteriaId":"CCD5D4AD-0BA3-42F7-852F-524488D74A96"},{"vulnerable":true,"criteria":"cpe:2.3:a:bea:weblogic_server:7.0:*:express:*:*:*:*:*","matchCriteriaId":"FBDF3AC0-0680-4EEE-898C-47D194667BE2"}]}]}],"references":[{"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/8357","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/SA_BEA03_36.00.jsp","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/8357","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2004-1798","sourceIdentifier":"cve@mitre.org","published":"2004-12-31T05:00:00.000","lastModified":"2026-06-16T22:08:25.403","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the \"My Computer\" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a \"file:javascript:\" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_enterprise_desktop:6.0.11.774:*:*:*:*:*:*:*","matchCriteriaId":"27DDB6F2-9EAF-4A77-BB3B-D3989E1D9458"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*","matchCriteriaId":"7E940DAB-0CD5-4EC0-916F-6C0B2AE26D19"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*","matchCriteriaId":"CF6535A6-6647-4E60-B5AA-24DFC06360AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.10.505:*:*:*:*:*:*:*","matchCriteriaId":"B04AEBE0-0160-4EA0-A177-BB66B2A842CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.818:*:*:*:*:*:*:*","matchCriteriaId":"0C6BB6A9-B0CE-4C04-8481-53B7CB195264"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.830:*:*:*:*:*:*:*","matchCriteriaId":"41688192-70B7-4C35-AE4F-FE116104137A"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.841:*:*:*:*:*:*:*","matchCriteriaId":"FA11D9CD-113B-4977-B150-D6500552222A"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.853:*:*:*:*:*:*:*","matchCriteriaId":"BF391DD1-2912-49BF-BC9F-B9FA3771737F"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.868:*:*:*:*:*:*:*","matchCriteriaId":"3908DB26-D8C4-4368-A1B6-C067085CE4B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:8.0:*:*:*:*:*:*:*","matchCriteriaId":"4E6051B4-1B15-44C0-B2CD-5504E68C60F2"}]}]}],"references":[{"url":"http://secunia.com/advisories/9584","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://securitytracker.com/id?1008647","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.osvdb.org/3826","source":"cve@mitre.org","tags":["Broken Link","Patch"]},{"url":"http://www.securityfocus.com/archive/1/349086","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/9378","source":"cve@mitre.org","tags":["Exploit","Patch","Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14168","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://secunia.com/advisories/9584","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://securitytracker.com/id?1008647","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.osvdb.org/3826","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"]},{"url":"http://www.securityfocus.com/archive/1/349086","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/9378","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14168","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]}]}},{"cve":{"id":"CVE-2006-0277","sourceIdentifier":"cve@mitre.org","published":"2006-01-18T11:03:00.000","lastModified":"2026-06-16T22:20:14.620","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":true,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*","matchCriteriaId":"C9B1BE09-4A96-41A3-AA1D-74533F396998"}]}]}],"references":[{"url":"http://secunia.com/advisories/18493","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/18608","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1015499","source":"cve@mitre.org"},{"url":"http://www.kb.cert.org/vuls/id/545804","source":"cve@mitre.org","tags":["US Government Resource"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/16287","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2006/0243","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2006/0323","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24321","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/18493","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/18608","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1015499","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.kb.cert.org/vuls/id/545804","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/16287","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2006/0243","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2006/0323","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24321","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2006-0732","sourceIdentifier":"cve@mitre.org","published":"2006-02-16T11:02:00.000","lastModified":"2026-06-16T22:21:10.330","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle.  Details will be updated after the grace period has ended.  NOTE: SAP Business Connector is an OEM version of webMethods Integration Server.  webMethods states that this issue can only occur when the product is installed as root/admin, and if the attacker has access to a general purpose port; however, both are discouraged in the documentation.  In addition, the attacker must already have acquired administrative privileges through other means."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_connector:4.6:*:*:*:*:*:*:*","matchCriteriaId":"AE83F111-0035-4740-87A8-02425B9F3A4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sap:business_connector:4.7:*:*:*:*:*:*:*","matchCriteriaId":"3C1A6DBC-631B-4FB4-8B10-31F891B23577"}]}]}],"references":[{"url":"http://secunia.com/advisories/18880","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1015639","source":"cve@mitre.org"},{"url":"http://securitytracker.com/id?1016090","source":"cve@mitre.org"},{"url":"http://securitytracker.com/id?1016122","source":"cve@mitre.org"},{"url":"http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf","source":"cve@mitre.org"},{"url":"http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/425048/100/0/threaded","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/434014/30/4980/threaded","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/16668","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2006/0611","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/18880","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://securitytracker.com/id?1015639","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://securitytracker.com/id?1016090","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://securitytracker.com/id?1016122","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.cybsec.com/vuln/CYBSEC_Security_Pre-Advisory_Arbitrary_File_Read_or_Delete_in_SAP_BC.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/425048/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/archive/1/434014/30/4980/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/16668","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2006/0611","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorSolution":"Apply patches (see SAP note 906401 and 908349)."}},{"cve":{"id":"CVE-2006-2166","sourceIdentifier":"cve@mitre.org","published":"2006-05-04T12:38:00.000","lastModified":"2026-06-16T22:24:28.017","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:N/I:P/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:unity_express_software:1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"05328FC0-D20B-44AD-A72B-19D125553067"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:unity_express_software:2.1.1:*:*:*:*:*:*:*","matchCriteriaId":"31397846-474A-46B3-8210-ADC20B93E4A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:unity_express_software:2.2.2:*:*:*:*:*:*:*","matchCriteriaId":"68CE1AB1-1745-4C19-B3AC-72A033D69F87"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unity_express:*:*:*:*:*:*:*:*","matchCriteriaId":"7583D706-3702-4571-BD2C-527E5337F6E1"}]}]}],"references":[{"url":"http://secunia.com/advisories/19881","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://securitytracker.com/id?1016015","source":"cve@mitre.org"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20060501-cue.shtml","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.osvdb.org/25165","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/17775","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2006/1613","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26165","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/19881","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://securitytracker.com/id?1016015","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20060501-cue.shtml","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.osvdb.org/25165","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/17775","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2006/1613","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26165","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2006-2361","sourceIdentifier":"cve@mitre.org","published":"2006-05-15T16:06:00.000","lastModified":"2026-06-16T22:24:51.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mxbb:mxbb_portal:2.7:*:*:*:*:*:*:*","matchCriteriaId":"B52A9BEC-1475-4C98-BB86-C198744FF65E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mxbb:mxbb_portal:2.8:*:*:*:*:*:*:*","matchCriteriaId":"B2C48A50-0868-4A44-8A71-A504B2FC7408"},{"vulnerable":true,"criteria":"cpe:2.3:a:php_arena:pafiledb:1.1.3:*:*:*:*:*:*:*","matchCriteriaId":"12BADFC3-51C0-4881-B5DF-81BBA02F0EAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:php_arena:pafiledb:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"EB092C95-F759-43A0-A1F5-40CD98369C25"}]}]}],"references":[{"url":"http://secunia.com/advisories/20062","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.osvdb.org/25507","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/17930","source":"cve@mitre.org","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2006/1776","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26496","source":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/1774","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/20062","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.osvdb.org/25507","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/17930","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"http://www.vupen.com/english/advisories/2006/1776","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26496","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/1774","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}