Latest CVE Feed
-
7.2
HIGHCVE-2004-0834
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.... Read more
- EPSS Score: %0.05
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0749
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and oth... Read more
- EPSS Score: %0.62
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0841
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability.... Read more
- EPSS Score: %39.61
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0805
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.... Read more
- EPSS Score: %5.84
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1373
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.... Read more
Affected Products : shoutcast_server- EPSS Score: %86.85
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0833
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.... Read more
Affected Products : debian_linux- EPSS Score: %0.66
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1337
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.... Read more
- EPSS Score: %0.05
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0867
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was la... Read more
- EPSS Score: %3.64
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0873
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.... Read more
- EPSS Score: %0.64
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0849
Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP r... Read more
Affected Products : radius- EPSS Score: %0.74
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0850
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.... Read more
Affected Products : star_tape_archiver- EPSS Score: %0.07
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0646
Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-T... Read more
- EPSS Score: %70.95
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0810
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.... Read more
Affected Products : timbuktu_pro_mac- EPSS Score: %1.39
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0512
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.... Read more
Affected Products : openserver- EPSS Score: %0.07
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1778
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.... Read more
Affected Products : skype- EPSS Score: %0.06
- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0068
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blin... Read more
Affected Products : tcp- EPSS Score: %2.24
- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0066
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number ... Read more
Affected Products : tcp- EPSS Score: %1.23
- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0067
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated usi... Read more
Affected Products : tcp- EPSS Score: %1.23
- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0441
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a cr... Read more
Affected Products : adaptive_server_enterprise- EPSS Score: %21.28
- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be alloca... Read more
Affected Products : solaris sunos mac_os_x mac_os_x_server libtiff unixware modular_messaging_message_storage_server propack linux linux +10 more products- EPSS Score: %5.11
- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025