Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2004-0387

    Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.... Read more

    Affected Products : realplayer realone_player
    • EPSS Score: %6.29
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2004-0389

    RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.... Read more

    Affected Products : helix_universal_server
    • EPSS Score: %8.06
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0118

    The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.... Read more

    Affected Products : windows_2000 windows_nt
    • EPSS Score: %12.67
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0133

    The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.06
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0182

    Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.... Read more

    Affected Products : mailman
    • EPSS Score: %0.57
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0533

    Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Wind... Read more

    • EPSS Score: %88.78
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.6

    HIGH
    CVE-2003-0906

    Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF im... Read more

    Affected Products : windows_2000 windows_xp windows_nt
    • EPSS Score: %45.30
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2041

    PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.... Read more

    Affected Products : e107
    • EPSS Score: %2.14
    • Published: May. 29, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-2039

    e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error mes... Read more

    Affected Products : e107
    • EPSS Score: %0.98
    • Published: May. 29, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2042

    Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.... Read more

    Affected Products : e107
    • EPSS Score: %3.26
    • Published: May. 29, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-2038

    Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.... Read more

    Affected Products : land_down_under
    • EPSS Score: %11.04
    • Published: May. 29, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-2040

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg p... Read more

    Affected Products : e107
    • EPSS Score: %2.01
    • Published: May. 29, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2036

    SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.... Read more

    Affected Products : jportal_web_portal
    • EPSS Score: %1.16
    • Published: May. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-2033

    Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.... Read more

    Affected Products : orenosv_http_ftp_server
    • EPSS Score: %17.63
    • Published: May. 26, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-2035

    MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.... Read more

    Affected Products : minimal_http_server
    • EPSS Score: %9.19
    • Published: May. 26, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-2135

    cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.46
    • Published: May. 26, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2032

    Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.... Read more

    Affected Products : rp114
    • EPSS Score: %4.00
    • Published: May. 24, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-2029

    The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.... Read more

    Affected Products : bnbt
    • EPSS Score: %11.98
    • Published: May. 22, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-2030

    Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.... Read more

    Affected Products : liferay_enterprise_portal
    • EPSS Score: %1.62
    • Published: May. 22, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-2031

    Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.... Read more

    Affected Products : e107
    • EPSS Score: %0.56
    • Published: May. 21, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291570 Results