Latest CVE Feed
-
10.0
HIGHCVE-2004-1402
SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.... Read more
Affected Products : iwebnegar- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1396
Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.... Read more
Affected Products : winamp- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2387
Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1564
CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.... Read more
Affected Products : w-agora- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1146
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.... Read more
Affected Products : cvstrac- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1897
Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-... Read more
Affected Products : monit- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1554
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : alex_guestbook- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0951
The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0919
The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.... Read more
Affected Products : freebsd- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0907
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitra... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-1049
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon F... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0979
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended conf... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0985
Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to wr... Read more
Affected Products : ie- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0829
smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.... Read more
Affected Products : samba- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0999
zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images.... Read more
Affected Products : zgv_image_viewer- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0811
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.... Read more
Affected Products : http_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0806
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.... Read more
Affected Products : cdrecord- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1200
Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.... Read more
Affected Products : firefox- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1236
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.... Read more
Affected Products : directory_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0090
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025