Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-0688

    Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malfo... Read more

    Affected Products : suse_linux openbsd x11r6 x11r6
    • EPSS Score: %16.03
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0795

    DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.... Read more

    Affected Products : db2_universal_database
    • EPSS Score: %31.91
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1016

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplic... Read more

    • EPSS Score: %0.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0051

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3... Read more

    • EPSS Score: %0.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0162

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.... Read more

    • EPSS Score: %0.34
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0793

    The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more

    Affected Products : bsdmainutils
    • EPSS Score: %0.05
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0754

    Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.... Read more

    Affected Products : enterprise_linux gaim
    • EPSS Score: %5.60
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2004-0792

    Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.... Read more

    Affected Products : rsync
    • EPSS Score: %0.84
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0748

    mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.... Read more

    Affected Products : http_server
    • EPSS Score: %19.65
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0784

    The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.... Read more

    Affected Products : enterprise_linux gaim
    • EPSS Score: %1.27
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0778

    CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.... Read more

    Affected Products : cvs
    • EPSS Score: %4.74
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1380

    Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing ... Read more

    Affected Products : firefox mozilla
    • EPSS Score: %14.50
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1381

    Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other site... Read more

    Affected Products : firefox mozilla
    • EPSS Score: %13.49
    • Published: Oct. 20, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-1353

    Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %0.06
    • Published: Oct. 19, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1618

    Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.... Read more

    Affected Products : tonecast
    • EPSS Score: %1.13
    • Published: Oct. 19, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1607

    slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %0.68
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1616

    Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.... Read more

    Affected Products : links
    • EPSS Score: %1.30
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1612

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.... Read more

    Affected Products : saleslogix
    • EPSS Score: %12.81
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.5

    MEDIUM
    CVE-2004-1603

    cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.... Read more

    Affected Products : cpanel
    • EPSS Score: %0.12
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1608

    SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.... Read more

    Affected Products : saleslogix saleslogix
    • EPSS Score: %0.96
    • Published: Oct. 18, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291737 Results