Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2004-0786

    The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.... Read more

    Affected Products : http_server
    • EPSS Score: %52.18
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0768

    libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.... Read more

    Affected Products : libpng3
    • EPSS Score: %4.10
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0797

    The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).... Read more

    Affected Products : zlib
    • EPSS Score: %0.76
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0796

    SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.... Read more

    Affected Products : spamassassin
    • EPSS Score: %1.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0755

    The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.... Read more

    Affected Products : ruby
    • EPSS Score: %0.06
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-1353

    Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %0.06
    • Published: Oct. 19, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1618

    Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.... Read more

    Affected Products : tonecast
    • EPSS Score: %1.13
    • Published: Oct. 19, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1608

    SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %0.96
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1612

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.... Read more

    Affected Products : saleslogix
    • EPSS Score: %12.81
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2004-1603

    cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.... Read more

    Affected Products : cpanel
    • EPSS Score: %0.12
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1616

    Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.... Read more

    Affected Products : links
    • EPSS Score: %1.30
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1607

    slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %0.68
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1621

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the begi... Read more

    Affected Products : lotus_domino
    • EPSS Score: %1.91
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1613

    Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing char... Read more

    • EPSS Score: %1.80
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1614

    Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.... Read more

    Affected Products : mozilla
    • EPSS Score: %1.13
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2004-1606

    slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %1.80
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2004-1611

    SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obta... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %1.50
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1617

    Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an ... Read more

    Affected Products : lynx
    • EPSS Score: %3.67
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1609

    SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %0.76
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1610

    SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %1.73
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291589 Results