Latest CVE Feed
-
7.5
HIGHCVE-2004-2368
PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath parameter.... Read more
Affected Products : opt-x- EPSS Score: %1.51
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2373
The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.... Read more
Affected Products : instant_messenger- EPSS Score: %3.06
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2375
Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an APOP USER command with a long second parameter (digest).... Read more
Affected Products : 1st_class_mail_server- EPSS Score: %10.34
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-2388
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.... Read more
Affected Products : aix- EPSS Score: %1.01
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2401
Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."... Read more
Affected Products : imail_express- EPSS Score: %1.41
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-2405
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA arch... Read more
Affected Products : f-secure_anti-virus internet_gatekeeper f-secure_internet_security f-secure_for_firewalls- EPSS Score: %0.34
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2668
SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : interchange- EPSS Score: %0.42
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-2493
Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.... Read more
- EPSS Score: %1.22
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2494
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.... Read more
Affected Products : ability_mail_server- EPSS Score: %1.22
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-2747
Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which trigge... Read more
Affected Products : quick_n_easy_ftp_server- EPSS Score: %0.26
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2318
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.... Read more
Affected Products : surgeftp- EPSS Score: %1.62
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-2298
Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential b... Read more
- EPSS Score: %0.38
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2144
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.... Read more
Affected Products : baal_smart_forms- EPSS Score: %0.64
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2191
Cross-site scripting (XSS) vulnerability in ttt-webmaster.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) msg[0] or (2) siteurl parameters.... Read more
Affected Products : turbotraffictrader_php- EPSS Score: %0.62
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2123
Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and po... Read more
Affected Products : e-commerce_asp_engine- EPSS Score: %0.30
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-2675
ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted.... Read more
Affected Products : ftp_server- EPSS Score: %5.78
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2352
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.... Read more
Affected Products : gbook- EPSS Score: %0.41
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-2235
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.... Read more
Affected Products : moodle- EPSS Score: %0.38
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-2357
The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.... Read more
Affected Products : proofpoint_protection_server- EPSS Score: %0.38
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-2622
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.... Read more
Affected Products : deployment_server_extension_for_ibm_director- EPSS Score: %1.73
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025