Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0610
The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.... Read more
Affected Products : mn-500_wireless_base_station- EPSS Score: %19.17
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0625
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.... Read more
Affected Products : infinity_web- EPSS Score: %0.81
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0627
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.... Read more
Affected Products : mysql- EPSS Score: %49.14
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0602
The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system panic.... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0611
Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.... Read more
Affected Products : fvs318- EPSS Score: %0.65
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0613
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.... Read more
Affected Products : osticket_sts- EPSS Score: %6.78
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0617
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.... Read more
Affected Products : arbitroweb- EPSS Score: %1.79
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0606
Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.... Read more
Affected Products : dns_one_appliance- EPSS Score: %1.96
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0621
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.... Read more
Affected Products : newsletter_zws- EPSS Score: %2.94
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0590
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-sig... Read more
- EPSS Score: %0.58
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0604
The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.... Read more
- EPSS Score: %1.27
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0455
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.... Read more
- EPSS Score: %0.14
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0618
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.... Read more
Affected Products : freebsd- EPSS Score: %0.23
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0395
The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.... Read more
Affected Products : gatos- EPSS Score: %0.06
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0448
Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.... Read more
Affected Products : jftpgw- EPSS Score: %2.46
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0626
The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negat... Read more
- EPSS Score: %1.74
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0608
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and ea... Read more
Affected Products : unreal_tournament_2004 linux unreal_engine unreal_tournament_2003 unreal_tournament devastation tnn_outdoors_pro_hunter tacticalops x-com_enforcer deusex +4 more products- EPSS Score: %60.18
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0609
rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.... Read more
Affected Products : rssh- EPSS Score: %0.39
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0577
WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to the wingate-internal directory.... Read more
Affected Products : wingate- EPSS Score: %0.39
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0616
The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.... Read more
Affected Products : voyager_2000_wireless_adsl_router- EPSS Score: %3.57
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025