Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0869
Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, ak... Read more
Affected Products : ie- EPSS Score: %15.68
- Published: Sep. 16, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0871
Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross S... Read more
Affected Products : mozilla- EPSS Score: %0.44
- Published: Sep. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1379
Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first fiel... Read more
- EPSS Score: %3.54
- Published: Sep. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1685
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_stat... Read more
- EPSS Score: %0.94
- Published: Sep. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1686
Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrate... Read more
Affected Products : ie- EPSS Score: %10.70
- Published: Sep. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0905
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame o... Read more
- EPSS Score: %5.74
- Published: Sep. 14, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0831
McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.... Read more
Affected Products : virusscan- EPSS Score: %0.05
- Published: Sep. 14, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0838
Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.... Read more
Affected Products : jumpdrive_secure- EPSS Score: %0.04
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2004-1683
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.... Read more
Affected Products : rtos- EPSS Score: %0.07
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0807
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.... Read more
- EPSS Score: %9.85
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1680
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.... Read more
Affected Products : xpressa- EPSS Score: %1.00
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1684
Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- EPSS Score: %0.40
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1678
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can lea... Read more
Affected Products : perldesk- EPSS Score: %5.10
- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1677
pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.... Read more
Affected Products : perldesk- EPSS Score: %0.46
- Published: Sep. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1676
Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.... Read more
Affected Products : gadu-gadu_instant_messenger- EPSS Score: %6.17
- Published: Sep. 12, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1675
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.... Read more
Affected Products : serv-u_file_server- EPSS Score: %10.74
- Published: Sep. 11, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1669
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Sear... Read more
- EPSS Score: %0.38
- Published: Sep. 10, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1670
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) re... Read more
- EPSS Score: %1.03
- Published: Sep. 10, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1668
Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.... Read more
Affected Products : factory_subjects_module- EPSS Score: %0.93
- Published: Sep. 10, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0830
The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (... Read more
- EPSS Score: %1.08
- Published: Sep. 09, 2004
- Modified: Apr. 03, 2025