Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1720
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an... Read more
Affected Products : mail_server- EPSS Score: %9.09
- Published: Aug. 17, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1716
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.... Read more
Affected Products : pforum- EPSS Score: %7.72
- Published: Aug. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1717
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.... Read more
Affected Products : gv- EPSS Score: %9.38
- Published: Aug. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1737
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.... Read more
- EPSS Score: %3.85
- Published: Aug. 16, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1682
Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.... Read more
Affected Products : rtp- EPSS Score: %0.70
- Published: Aug. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1715
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.... Read more
Affected Products : mimesweeper_for_web- EPSS Score: %1.05
- Published: Aug. 11, 2004
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2004-1714
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as de... Read more
- EPSS Score: %0.14
- Published: Aug. 11, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1347
X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.... Read more
- EPSS Score: %3.38
- Published: Aug. 10, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1713
Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.... Read more
- EPSS Score: %0.17
- Published: Aug. 10, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1701
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.... Read more
Affected Products : cfengine- EPSS Score: %56.76
- Published: Aug. 09, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1702
The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers... Read more
Affected Products : cfengine- EPSS Score: %2.12
- Published: Aug. 09, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0527
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facil... Read more
Affected Products : konqueror- EPSS Score: %2.83
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0550
Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of "." (period) characters.... Read more
Affected Products : realplayer- EPSS Score: %11.25
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0548
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) ... Read more
- EPSS Score: %0.18
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0536
Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.... Read more
Affected Products : tripwire- EPSS Score: %0.08
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0545
LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : aix- EPSS Score: %0.05
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0716
Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amount of data.... Read more
Affected Products : hp-ux- EPSS Score: %4.29
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0650
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.... Read more
Affected Products : servletexec- EPSS Score: %1.38
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0669
Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.... Read more
Affected Products : lotus_domino- EPSS Score: %0.64
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0529
The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such a... Read more
Affected Products : suexec.patch- EPSS Score: %0.55
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025