Latest CVE Feed
-
10.0
HIGHCVE-2004-0214
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share ... Read more
- EPSS Score: %73.83
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-0847
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation... Read more
- EPSS Score: %64.44
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0911
telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.... Read more
Affected Products : netkit- EPSS Score: %0.93
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0846
Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.... Read more
- EPSS Score: %51.44
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0774
RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.... Read more
- EPSS Score: %0.68
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0844
Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byt... Read more
Affected Products : ie- EPSS Score: %53.43
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0835
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorize... Read more
- EPSS Score: %3.65
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0804
Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.... Read more
Affected Products : libtiff- EPSS Score: %19.17
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0718
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements wit... Read more
- EPSS Score: %52.24
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0207
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions... Read more
- EPSS Score: %1.59
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1121
Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.... Read more
Affected Products : safari- EPSS Score: %3.23
- Published: Nov. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1350
Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.... Read more
Affected Products : java_system_web_proxy_server- EPSS Score: %25.41
- Published: Oct. 30, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1636
Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.... Read more
Affected Products : wvtftp- EPSS Score: %6.82
- Published: Oct. 26, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1637
The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.... Read more
Affected Products : har11a_dsl_router- EPSS Score: %0.72
- Published: Oct. 26, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1639
Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.... Read more
- EPSS Score: %0.89
- Published: Oct. 26, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1631
Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.... Read more
Affected Products : work_flow_engine- EPSS Score: %0.44
- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1633
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.... Read more
Affected Products : bugzilla- EPSS Score: %0.29
- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1634
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive informa... Read more
Affected Products : bugzilla- EPSS Score: %0.44
- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1632
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.... Read more
Affected Products : moniwiki- EPSS Score: %0.44
- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1630
Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.... Read more
Affected Products : work_flow_engine- EPSS Score: %0.44
- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025