Latest CVE Feed
-
2.1
LOWCVE-2005-0318
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.... Read more
Affected Products : webadmin- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0313
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote au... Read more
Affected Products : magic_winmail_server- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0922
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows att... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2004-0880
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0930
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop samba linux_advanced_workstation linux linux fedora_core samba- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0929
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0903
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments tha... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0892
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed ... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0887
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0917
The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities vi... Read more
Affected Products : application_portal- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0935
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0932
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which doe... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0933
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remot... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0314
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.... Read more
Affected Products : magic_winmail_server- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0884
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious p... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0923
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0926
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0889
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-20... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop xpdf suse_linux xpdf gpdf kpdf ubuntu_linux linux_advanced_workstation +8 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0916
Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.... Read more
Affected Products : cabextract- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0918
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocat... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025