Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-0935

    Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system... Read more

    • EPSS Score: %13.20
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0922

    AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows att... Read more

    Affected Products : quicktime mac_os_x mac_os_x_server
    • EPSS Score: %0.30
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0927

    ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.... Read more

    Affected Products : mac_os_x mac_os_x_server cups
    • EPSS Score: %0.19
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0921

    AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.... Read more

    Affected Products : quicktime mac_os_x mac_os_x_server
    • EPSS Score: %0.41
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0313

    Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote au... Read more

    Affected Products : magic_winmail_server
    • EPSS Score: %8.79
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0882

    Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.... Read more

    • EPSS Score: %33.01
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0891

    Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded co... Read more

    • EPSS Score: %5.44
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-0315

    The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for por... Read more

    Affected Products : magic_winmail_server
    • EPSS Score: %0.36
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0925

    Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %0.48
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0888

    Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities ... Read more

    • EPSS Score: %4.44
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0314

    Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.... Read more

    Affected Products : magic_winmail_server
    • EPSS Score: %0.43
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0892

    Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed ... Read more

    • EPSS Score: %11.51
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0889

    Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-20... Read more

    • EPSS Score: %3.39
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0916

    Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.... Read more

    Affected Products : cabextract
    • EPSS Score: %1.94
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0918

    The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocat... Read more

    • EPSS Score: %68.74
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2004-0880

    getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.... Read more

    Affected Products : linux slackware_linux getmail
    • EPSS Score: %0.10
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0929

    Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.... Read more

    Affected Products : libtiff suse_linux
    • EPSS Score: %8.16
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0903

    Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments tha... Read more

    • EPSS Score: %18.83
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0930

    The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.... Read more

    • EPSS Score: %6.06
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0902

    Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" ... Read more

    • EPSS Score: %18.82
    • Published: Jan. 27, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 292762 Results