Latest CVE Feed
-
10.0
HIGHCVE-2004-1302
The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.... Read more
Affected Products : yamt- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1157
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window ... Read more
Affected Products : opera_browser- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1161
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1098
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1219
paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and... Read more
Affected Products : pafiledb- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1011
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1063
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in t... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1111
Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to ... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1162
The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1148
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.... Read more
Affected Products : phpmyadmin- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1127
Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.... Read more
Affected Products : direct_connect_peer-to-peer_client- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1195
Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.... Read more
Affected Products : star_wars_battlefront- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1075
Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error messag... Read more
Affected Products : zwiki- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1298
Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file.... Read more
Affected Products : vb2c- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0139
Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.... Read more
Affected Products : irix- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1172
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.... Read more
Affected Products : backup_exec- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1099
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1223
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.... Read more
Affected Products : policy_manager- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1217
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.... Read more
Affected Products : hosting_controller- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1221
Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.... Read more
Affected Products : weblibs- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025