Latest CVE Feed
-
10.0
HIGHCVE-2004-0982
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.... Read more
Affected Products : mpg123- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0967
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : ghostscript- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0976
Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : perl- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0962
Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switch... Read more
Affected Products : apple_remote_desktop- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0937
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compre... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0975
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : openssl linux mandrake_linux mandrake_linux_corporate_server mandrake_multi_network_firewall- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0362
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.... Read more
Affected Products : awstats- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0963
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0947
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0981
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0971
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : kerberos_5- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0961
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0980
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0970
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.... Read more
Affected Products : gzip- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0848
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.... Read more
- Published: Feb. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0233
The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph ... Read more
- Published: Feb. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0249
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.... Read more
Affected Products : brightmail_antispam mail_security norton_system_works client_security norton_antivirus norton_internet_security web_security antivirus_scan_engine gateway_security sav_filter_domino_nt_ports +1 more products- Published: Feb. 08, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0175
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.... Read more
Affected Products : squid- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0231
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."... Read more
Affected Products : firefox- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1131
Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : openserver- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025