Latest CVE Feed
-
10.0
HIGHCVE-2004-0891
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded co... Read more
- EPSS Score: %5.44
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2004-0880
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.... Read more
- EPSS Score: %0.10
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0313
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote au... Read more
Affected Products : magic_winmail_server- EPSS Score: %8.79
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0314
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.... Read more
Affected Products : magic_winmail_server- EPSS Score: %0.43
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0892
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed ... Read more
- EPSS Score: %11.51
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0926
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.... Read more
- EPSS Score: %3.66
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0884
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious p... Read more
- EPSS Score: %0.06
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0923
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.... Read more
- EPSS Score: %0.12
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0903
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments tha... Read more
- EPSS Score: %18.83
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0929
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.... Read more
- EPSS Score: %8.16
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0930
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop samba linux_advanced_workstation linux linux fedora_core samba- EPSS Score: %6.06
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0902
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" ... Read more
- EPSS Score: %18.82
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0934
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- EPSS Score: %39.95
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0924
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.... Read more
- EPSS Score: %0.30
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0881
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.... Read more
- EPSS Score: %0.09
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0936
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- EPSS Score: %13.20
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0886
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop mac_os_x mac_os_x_server libtiff suse_linux linux_advanced_workstation mandrake_linux fedora_core secure_linux +3 more products- EPSS Score: %10.99
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0312
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a for... Read more
Affected Products : war_ftp_daemon- EPSS Score: %1.33
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0927
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.... Read more
- EPSS Score: %0.19
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0921
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.... Read more
- EPSS Score: %0.41
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025