Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-1820

    PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains f... Read more

    Affected Products : 4nalbum_module
    • EPSS Score: %3.71
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1817

    Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) s... Read more

    Affected Products : php-nuke
    • EPSS Score: %5.68
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0166

    Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %0.35
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0167

    DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %1.33
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0190

    Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.... Read more

    • EPSS Score: %0.75
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1815

    Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).... Read more

    Affected Products : one_application_server coldfusion jrun
    • EPSS Score: %8.59
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1822

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target p... Read more

    Affected Products : phorum
    • EPSS Score: %1.30
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0185

    Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.... Read more

    Affected Products : wu-ftpd
    • EPSS Score: %7.26
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0171

    FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from ... Read more

    Affected Products : freebsd openbsd
    • EPSS Score: %1.42
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1827

    Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.... Read more

    Affected Products : yabb simple_machines_smf
    • EPSS Score: %0.87
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1819

    4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.... Read more

    Affected Products : 4nalbum_module
    • EPSS Score: %0.62
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1816

    Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).... Read more

    Affected Products : one_application_server coldfusion jrun
    • EPSS Score: %1.73
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0165

    Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %1.78
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2004-0192

    Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the result... Read more

    Affected Products : gateway_security_5400
    • EPSS Score: %0.53
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0172

    Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a ... Read more

    Affected Products : ltrace
    • EPSS Score: %0.05
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0159

    Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.... Read more

    Affected Products : hsftp
    • EPSS Score: %10.29
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0188

    Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.... Read more

    Affected Products : calife
    • EPSS Score: %0.05
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0110

    Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.... Read more

    Affected Products : libxml2 propack libxml
    • EPSS Score: %45.17
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0168

    Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %1.22
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1821

    SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.... Read more

    Affected Products : 4nalbum_module
    • EPSS Score: %0.45
    • Published: Mar. 15, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291265 Results