Latest CVE Feed
-
10.0
HIGHCVE-2004-1137
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1106
Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1264
Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.... Read more
Affected Products : chbg- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1019
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and ... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1098
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1054
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has be... Read more
Affected Products : aix- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2004-1066
The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel me... Read more
Affected Products : freebsd- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1023
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, in... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1229
Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1291
Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.... Read more
Affected Products : qwik_smtpd- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1272
Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message.... Read more
Affected Products : filter- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1293
Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.... Read more
Affected Products : rtf2latex2e- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1225
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.... Read more
Affected Products : sugarcrm- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1262
Buffer overflow in the bsb_open_header function in libbsb for bsb2ppm 0.0.6 allows remote attackers to execute arbitrary code via crafted BSB pictures.... Read more
Affected Products : bsb2ppm- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1431
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such a... Read more
Affected Products : zero_administration_kit- Published: Jan. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0182
The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : mod_dosevasive- Published: Jan. 06, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-1183
Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.... Read more
Affected Products : libtiff- Published: Jan. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1318
Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being prop... Read more
Affected Products : namazu- Published: Jan. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1373
FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.... Read more
Affected Products : powerhub_software- Published: Jan. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0283
Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.... Read more
Affected Products : qwikiwiki- Published: Jan. 04, 2005
- Modified: Apr. 03, 2025