Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2004-0371

    Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.... Read more

    Affected Products : heimdal
    • EPSS Score: %0.65
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0376

    oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.... Read more

    Affected Products : oftpd
    • EPSS Score: %1.27
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0184

    Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, wh... Read more

    Affected Products : tcpdump
    • EPSS Score: %65.92
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0149

    Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.... Read more

    Affected Products : xboing
    • EPSS Score: %0.08
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0365

    The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.... Read more

    Affected Products : ethereal
    • EPSS Score: %29.82
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2004-0374

    Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.... Read more

    Affected Products : interchange
    • EPSS Score: %6.02
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0176

    Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.... Read more

    Affected Products : ethereal
    • EPSS Score: %68.69
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0386

    Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.... Read more

    Affected Products : mplayer linux mandrake_linux
    • EPSS Score: %34.06
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0218

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more

    Affected Products : openbsd openbsd
    • EPSS Score: %2.84
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0183

    TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Sui... Read more

    Affected Products : tcpdump
    • EPSS Score: %29.13
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0174

    Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening so... Read more

    Affected Products : http_server
    • EPSS Score: %31.44
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0222

    Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more

    Affected Products : openbsd openbsd
    • EPSS Score: %2.23
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0220

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demon... Read more

    Affected Products : openbsd openbsd
    • EPSS Score: %2.87
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0618

    Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.... Read more

    Affected Products : debian_linux suidperl
    • EPSS Score: %0.05
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0377

    Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.... Read more

    Affected Products : perl activeperl
    • EPSS Score: %10.19
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0383

    Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.07
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1993

    The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.... Read more

    Affected Products : omail_webmail
    • EPSS Score: %1.94
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1982

    Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.... Read more

    Affected Products : yabb
    • EPSS Score: %0.64
    • Published: May. 03, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1991

    Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more

    Affected Products : aldo\'s_web_server
    • EPSS Score: %3.15
    • Published: May. 03, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0428

    Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %0.67
    • Published: May. 03, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291419 Results