Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0222
Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more
- EPSS Score: %2.23
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0176
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.... Read more
Affected Products : ethereal- EPSS Score: %68.69
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1982
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.... Read more
Affected Products : yabb- EPSS Score: %0.64
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0428
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.... Read more
- EPSS Score: %0.67
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1991
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more
Affected Products : aldo\'s_web_server- EPSS Score: %3.15
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1983
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- EPSS Score: %0.21
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1981
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.... Read more
- EPSS Score: %0.65
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1984
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, wh... Read more
- EPSS Score: %0.55
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2043
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using ... Read more
- EPSS Score: %47.46
- Published: May. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1987
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.... Read more
- EPSS Score: %0.28
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1978
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.... Read more
Affected Products : moodle- EPSS Score: %3.64
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1988
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.... Read more
- EPSS Score: %0.08
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1980
Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.... Read more
Affected Products : props- EPSS Score: %0.44
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1989
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.i... Read more
- EPSS Score: %0.08
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1985
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.... Read more
- EPSS Score: %0.16
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1979
Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.... Read more
Affected Products : props- EPSS Score: %0.35
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1977
3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.... Read more
Affected Products : webbngss3nbxnts- EPSS Score: %1.23
- Published: Apr. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1976
SMC Barricade broadband router 7008ABR and 7004VBR enable remote administration by default, which allows remote attackers to gain access by connecting to port 1900.... Read more
Affected Products : smc7004vbr- EPSS Score: %0.91
- Published: Apr. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1973
DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes resources when DiGi converts the slashes to \ (backslash) characters.... Read more
Affected Products : www_server- EPSS Score: %10.46
- Published: Apr. 27, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1975
Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.... Read more
Affected Products : pafiledb- EPSS Score: %0.58
- Published: Apr. 27, 2004
- Modified: Apr. 03, 2025