Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2004-1634

    show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive informa... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.44
    • Published: Oct. 25, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1635

    Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remot... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.62
    • Published: Oct. 24, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1629

    Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.... Read more

    Affected Products : dwc_articles
    • EPSS Score: %0.49
    • Published: Oct. 23, 2004
    • Modified: Apr. 03, 2025
  • 9.0

    HIGH
    CVE-2004-1628

    Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.... Read more

    Affected Products : rssh
    • EPSS Score: %2.56
    • Published: Oct. 23, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1625

    pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.... Read more

    Affected Products : pgina
    • EPSS Score: %0.74
    • Published: Oct. 22, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1623

    The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.... Read more

    Affected Products : windows_xp
    • EPSS Score: %38.70
    • Published: Oct. 22, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1626

    Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.... Read more

    Affected Products : ability_server
    • EPSS Score: %73.36
    • Published: Oct. 22, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1627

    Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.... Read more

    Affected Products : ability_server
    • EPSS Score: %16.73
    • Published: Oct. 22, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1622

    SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.... Read more

    Affected Products : ubb.threads
    • EPSS Score: %0.33
    • Published: Oct. 21, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1620

    CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer f... Read more

    Affected Products : serendipity
    • EPSS Score: %8.35
    • Published: Oct. 21, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-1624

    Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button... Read more

    Affected Products : carbon_copy
    • EPSS Score: %0.05
    • Published: Oct. 21, 2004
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2004-0772

    Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.... Read more

    Affected Products : debian_linux kerberos_5 openpkg
    • EPSS Score: %21.77
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0161

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.... Read more

    • EPSS Score: %0.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0796

    SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.... Read more

    Affected Products : spamassassin
    • EPSS Score: %1.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0783

    Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ... Read more

    Affected Products : gdkpixbuf gtk
    • EPSS Score: %30.60
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0688

    Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malfo... Read more

    Affected Products : suse_linux openbsd x11r6 x11r6
    • EPSS Score: %16.03
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0785

    Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL... Read more

    Affected Products : enterprise_linux gaim
    • EPSS Score: %6.30
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0793

    The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more

    Affected Products : bsdmainutils
    • EPSS Score: %0.05
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1016

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplic... Read more

    • EPSS Score: %0.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-0787

    Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.... Read more

    Affected Products : openca
    • EPSS Score: %0.38
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291739 Results