Latest CVE Feed
-
7.5
HIGHCVE-2004-1627
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.... Read more
Affected Products : ability_server- EPSS Score: %16.73
- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1625
pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.... Read more
Affected Products : pgina- EPSS Score: %0.74
- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1623
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.... Read more
Affected Products : windows_xp- EPSS Score: %38.70
- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1620
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer f... Read more
Affected Products : serendipity- EPSS Score: %8.35
- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1622
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.... Read more
Affected Products : ubb.threads- EPSS Score: %0.33
- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1624
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button... Read more
Affected Products : carbon_copy- EPSS Score: %0.05
- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1015
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.... Read more
- EPSS Score: %0.34
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0792
Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.... Read more
Affected Products : rsync- EPSS Score: %0.84
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0754
Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.... Read more
- EPSS Score: %5.60
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0755
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.... Read more
Affected Products : ruby- EPSS Score: %0.06
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0784
The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.... Read more
- EPSS Score: %1.27
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0753
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.... Read more
- EPSS Score: %12.04
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0783
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ... Read more
- EPSS Score: %30.60
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0688
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malfo... Read more
- EPSS Score: %16.03
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0752
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.... Read more
Affected Products : openoffice- EPSS Score: %0.06
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.... Read more
- EPSS Score: %0.07
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0687
Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.... Read more
- EPSS Score: %19.95
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0746
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.... Read more
- EPSS Score: %1.50
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0747
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.... Read more
Affected Products : http_server- EPSS Score: %5.37
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0788
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.... Read more
- EPSS Score: %12.93
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025