Latest CVE Feed
-
2.1
LOWCVE-2004-0881
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0886
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop mac_os_x mac_os_x_server libtiff suse_linux linux_advanced_workstation mandrake_linux fedora_core secure_linux +3 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0924
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0936
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0315
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for por... Read more
Affected Products : magic_winmail_server- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0312
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a for... Read more
Affected Products : war_ftp_daemon- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0888
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities ... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop xpdf suse_linux xpdf gpdf kpdf ubuntu_linux linux_advanced_workstation +8 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0891
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded co... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0882
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop samba ubuntu_linux linux_advanced_workstation linux fedora_core- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0925
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0921
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0927
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0934
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0902
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" ... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0162
Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary ... Read more
- Published: Jan. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1340
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.... Read more
Affected Products : debian_linux- Published: Jan. 26, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1021
The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.... Read more
Affected Products : openserver- Published: Jan. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0096
Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).... Read more
Affected Products : squid- Published: Jan. 25, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0307
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.... Read more
Affected Products : mercuryboard- Published: Jan. 25, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0309
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.... Read more
Affected Products : exponent- Published: Jan. 25, 2005
- Modified: Apr. 03, 2025