Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2004-0869

    Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, ak... Read more

    Affected Products : ie
    • EPSS Score: %15.68
    • Published: Sep. 16, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0871

    Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross S... Read more

    Affected Products : mozilla
    • EPSS Score: %0.44
    • Published: Sep. 16, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1379

    Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first fiel... Read more

    Affected Products : xine-lib xine
    • EPSS Score: %3.54
    • Published: Sep. 16, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1685

    SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_stat... Read more

    Affected Products : smc7004vwbr smc7008abr
    • EPSS Score: %0.94
    • Published: Sep. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1686

    Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrate... Read more

    Affected Products : ie
    • EPSS Score: %10.70
    • Published: Sep. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0905

    Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame o... Read more

    • EPSS Score: %5.74
    • Published: Sep. 14, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0831

    McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.... Read more

    Affected Products : virusscan
    • EPSS Score: %0.05
    • Published: Sep. 14, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0838

    Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.... Read more

    Affected Products : jumpdrive_secure
    • EPSS Score: %0.04
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 3.7

    LOW
    CVE-2004-1683

    A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.... Read more

    Affected Products : rtos
    • EPSS Score: %0.07
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0807

    Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.... Read more

    Affected Products : samba suse_linux linux mandrake_linux samba
    • EPSS Score: %9.85
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1680

    application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.... Read more

    Affected Products : xpressa
    • EPSS Score: %1.00
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1684

    Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more

    Affected Products : prestige zynos
    • EPSS Score: %0.40
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1678

    Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can lea... Read more

    Affected Products : perldesk
    • EPSS Score: %5.10
    • Published: Sep. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1677

    pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.... Read more

    Affected Products : perldesk
    • EPSS Score: %0.46
    • Published: Sep. 12, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1676

    Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.... Read more

    Affected Products : gadu-gadu_instant_messenger
    • EPSS Score: %6.17
    • Published: Sep. 12, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1675

    Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.... Read more

    Affected Products : serv-u_file_server
    • EPSS Score: %10.74
    • Published: Sep. 11, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1669

    Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Sear... Read more

    Affected Products : web_mail mail_server
    • EPSS Score: %0.38
    • Published: Sep. 10, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1670

    Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) re... Read more

    Affected Products : web_mail mail_server
    • EPSS Score: %1.03
    • Published: Sep. 10, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1668

    Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.... Read more

    Affected Products : factory_subjects_module
    • EPSS Score: %0.93
    • Published: Sep. 10, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0830

    The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (... Read more

    • EPSS Score: %1.08
    • Published: Sep. 09, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291513 Results