Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0116
An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.... Read more
- EPSS Score: %50.04
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0403
Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.... Read more
- EPSS Score: %13.26
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0409
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.... Read more
Affected Products : xchat- EPSS Score: %26.77
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0124
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."... Read more
- EPSS Score: %36.36
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0807
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted reques... Read more
- EPSS Score: %34.48
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0177
The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions... Read more
Affected Products : linux_kernel- EPSS Score: %1.24
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0385
Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vaguen... Read more
- EPSS Score: %38.82
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0181
The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2042
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.... Read more
Affected Products : e107- EPSS Score: %3.26
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2039
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error mes... Read more
Affected Products : e107- EPSS Score: %0.98
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2041
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : e107- EPSS Score: %2.14
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2040
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg p... Read more
Affected Products : e107- EPSS Score: %2.01
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2038
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.... Read more
Affected Products : land_down_under- EPSS Score: %11.04
- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2036
SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.... Read more
Affected Products : jportal_web_portal- EPSS Score: %1.16
- Published: May. 28, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2135
cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.... Read more
Affected Products : linux_kernel- EPSS Score: %0.46
- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2035
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.... Read more
Affected Products : minimal_http_server- EPSS Score: %9.19
- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2033
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.... Read more
Affected Products : orenosv_http_ftp_server- EPSS Score: %17.63
- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2032
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.... Read more
Affected Products : rp114- EPSS Score: %4.00
- Published: May. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2029
The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.... Read more
Affected Products : bnbt- EPSS Score: %11.98
- Published: May. 22, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2030
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.... Read more
Affected Products : liferay_enterprise_portal- EPSS Score: %1.62
- Published: May. 22, 2004
- Modified: Apr. 03, 2025