Latest CVE Feed
-
7.5
HIGHCVE-2004-0065
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.... Read more
Affected Products : phpgedview- EPSS Score: %0.49
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0988
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.... Read more
- EPSS Score: %7.32
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0095
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.... Read more
Affected Products : epolicy_orchestrator- EPSS Score: %5.80
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0061
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.... Read more
Affected Products : www_file_share_pro- EPSS Score: %0.31
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0049
Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.... Read more
- EPSS Score: %0.78
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1032
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly in... Read more
Affected Products : pi3web- EPSS Score: %4.82
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0071
Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.... Read more
Affected Products : php- EPSS Score: %4.72
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0060
WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.... Read more
Affected Products : www_file_share_pro- EPSS Score: %0.66
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0067
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7... Read more
Affected Products : phpgedview- EPSS Score: %1.65
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0059
Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.... Read more
Affected Products : www_file_share_pro- EPSS Score: %0.28
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0004
The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trus... Read more
Affected Products : openca- EPSS Score: %0.98
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0063
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by acceptin... Read more
Affected Products : payshield_spp_library- EPSS Score: %0.60
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0070
PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : ezcontents- EPSS Score: %1.90
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0091
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. ... Read more
Affected Products : vbulletin- EPSS Score: %0.43
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0819
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test s... Read more
Affected Products : proxy_server- EPSS Score: %58.25
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0054
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 pro... Read more
Affected Products : ios- EPSS Score: %5.65
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0989
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.... Read more
- EPSS Score: %18.90
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0992
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.... Read more
Affected Products : mailman- EPSS Score: %0.52
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0055
The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.... Read more
Affected Products : tcpdump- EPSS Score: %31.32
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1030
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.... Read more
Affected Products : mini_remote_control_server- EPSS Score: %46.05
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025