Latest CVE Feed
-
10.0
HIGHCVE-2004-0393
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.... Read more
Affected Products : rlpr- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0454
Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.... Read more
Affected Products : rlpr- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0623
Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.... Read more
Affected Products : gnats- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0448
Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.... Read more
Affected Products : jftpgw- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0395
The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.... Read more
Affected Products : gatos- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0590
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-sig... Read more
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0611
Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.... Read more
Affected Products : fvs318- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0613
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.... Read more
Affected Products : osticket_sts- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0618
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.... Read more
Affected Products : freebsd- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0604
The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.... Read more
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0621
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.... Read more
Affected Products : newsletter_zws- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0610
The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.... Read more
Affected Products : mn-500_wireless_base_station- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0627
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.... Read more
Affected Products : mysql- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0606
Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.... Read more
Affected Products : dns_one_appliance- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0625
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.... Read more
Affected Products : infinity_web- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0455
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.... Read more
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0617
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.... Read more
Affected Products : arbitroweb- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0602
The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system panic.... Read more
Affected Products : freebsd- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0497
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.... Read more
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0635
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.... Read more
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025