Latest CVE Feed
-
7.5
HIGHCVE-2004-0117
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %41.60
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0806
Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %49.10
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0907
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.... Read more
- EPSS Score: %42.34
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0908
The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI,... Read more
Affected Products : windows_2000- EPSS Score: %4.32
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0909
Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."... Read more
Affected Products : windows_xp- EPSS Score: %14.12
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0389
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.... Read more
Affected Products : helix_universal_server- EPSS Score: %8.06
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0387
Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.... Read more
- EPSS Score: %6.29
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0197
Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.... Read more
Affected Products : jet- EPSS Score: %39.54
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0182
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.... Read more
Affected Products : mailman- EPSS Score: %0.57
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0133
The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0119
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit r... Read more
- EPSS Score: %39.70
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0178
The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of b... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0155
The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middl... Read more
- EPSS Score: %4.94
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0385
Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the outp... Read more
- EPSS Score: %0.50
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0156
Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : ssmtp- EPSS Score: %1.65
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0181
The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0123
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_nt windows_98se windows_me- EPSS Score: %48.57
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0407
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before t... Read more
Affected Products : coldfusion- EPSS Score: %3.85
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2039
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error mes... Read more
Affected Products : e107- EPSS Score: %0.98
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2038
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.... Read more
Affected Products : land_down_under- EPSS Score: %11.04
- Published: May. 29, 2004
- Modified: Apr. 03, 2025