Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0081
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop ios openssl hp-ux freebsd mac_os_x mac_os_x_server imanager bsafe_ssl-j +56 more products- EPSS Score: %2.80
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0282
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.... Read more
Affected Products : crob_ftp_server- EPSS Score: %4.31
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0494
Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.... Read more
- EPSS Score: %0.86
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0256
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.... Read more
Affected Products : libtool- EPSS Score: %0.10
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0254
Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.... Read more
Affected Products : discuz- EPSS Score: %2.50
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0247
The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.... Read more
- EPSS Score: %6.88
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0262
Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.... Read more
Affected Products : the_palace_client- EPSS Score: %5.70
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0284
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%... Read more
- EPSS Score: %11.27
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0281
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.... Read more
Affected Products : resin- EPSS Score: %9.77
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0327
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.... Read more
Affected Products : phpnewsmanager- EPSS Score: %4.27
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0295
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.... Read more
Affected Products : broker_ftp_server- EPSS Score: %4.89
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0315
Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.... Read more
Affected Products : voice- EPSS Score: %3.18
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0338
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.... Read more
Affected Products : invision_board- EPSS Score: %0.42
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0351
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.... Read more
Affected Products : spidersales- EPSS Score: %0.06
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0294
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.... Read more
Affected Products : yet_another_bulletin_board- EPSS Score: %1.44
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0272
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.... Read more
Affected Products : maxwebportal- EPSS Score: %0.69
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0275
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.... Read more
Affected Products : bosdates- EPSS Score: %0.47
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0264
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.... Read more
- EPSS Score: %5.82
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0286
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.... Read more
Affected Products : robotftp_server- EPSS Score: %11.65
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.0
MEDIUMCVE-2004-0347
Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.... Read more
Affected Products : netscreen-sa_5000_series- EPSS Score: %1.78
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025