Latest CVE Feed
-
7.5
HIGHCVE-2003-0514
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. t... Read more
Affected Products : safari- EPSS Score: %2.71
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0202
The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : metrics- EPSS Score: %0.07
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1578
The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is no... Read more
Affected Products : sap_r_3- EPSS Score: %1.26
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1939
Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.... Read more
Affected Products : zaep_antispam- EPSS Score: %0.88
- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1944
Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.... Read more
Affected Products : eudora- EPSS Score: %3.92
- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1936
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.... Read more
Affected Products : zonealarm- EPSS Score: %0.36
- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1929
SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.13
- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1756
BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other user... Read more
Affected Products : weblogic_server- EPSS Score: %1.80
- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1758
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.... Read more
Affected Products : weblogic_server- EPSS Score: %0.12
- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1928
The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %6.84
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1930
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.... Read more
Affected Products : php-nuke- EPSS Score: %0.17
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1060
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Se... Read more
- EPSS Score: %59.91
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1932
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.02
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1933
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.... Read more
Affected Products : ux- EPSS Score: %0.07
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1925
Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ran... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %0.42
- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1926
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country ... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %3.83
- Published: Apr. 11, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1924
Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %0.49
- Published: Apr. 11, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1923
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the w... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %6.16
- Published: Apr. 11, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1927
Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.... Read more
Affected Products : tikiwiki_cms\/groupware- EPSS Score: %4.58
- Published: Apr. 11, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1922
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a ... Read more
Affected Products : internet_explorer- EPSS Score: %5.10
- Published: Apr. 11, 2004
- Modified: Apr. 03, 2025