Latest CVE Feed
-
7.5
HIGHCVE-2004-1485
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1456
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.... Read more
Affected Products : cvstrac- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1390
Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscr... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1393
Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1413
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the ... Read more
Affected Products : esupport- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1467
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField ... Read more
Affected Products : egroupware- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-1306
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1399
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.... Read more
Affected Products : attachment_mod- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1468
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1234
load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL.... Read more
Affected Products : linux_kernel- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1198
Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1155
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web si... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1189
The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array in... Read more
Affected Products : kerberos_5- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-2730
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSus... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2757
Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.... Read more
Affected Products : ichain- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2748
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.... Read more
Affected Products : reporting_center- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0323
Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc ... Read more
Affected Products : xmb- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0325
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstra... Read more
Affected Products : typsoft_ftp_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2736
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.... Read more
Affected Products : helpdesk- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-2747
Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which trigge... Read more
Affected Products : quick_n_easy_ftp_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025