Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-0573

    Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.... Read more

    Affected Products : office word works publisher frontpage
    • EPSS Score: %40.53
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0930

    Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.... Read more

    Affected Products : mailsweeper
    • EPSS Score: %0.17
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-1049

    IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.... Read more

    Affected Products : db2_universal_database
    • EPSS Score: %0.05
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1050

    Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.... Read more

    Affected Products : db2
    • EPSS Score: %0.15
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0928

    Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.... Read more

    Affected Products : mailsweeper
    • EPSS Score: %0.31
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0105

    ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.... Read more

    Affected Products : servermask
    • EPSS Score: %0.64
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0163

    Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.... Read more

    Affected Products : secure_enterprise
    • EPSS Score: %0.74
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1051

    Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.... Read more

    Affected Products : db2
    • EPSS Score: %0.05
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0931

    Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.... Read more

    Affected Products : enforcer
    • EPSS Score: %0.74
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2004-0200

    Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a la... Read more

    • EPSS Score: %76.69
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0408

    Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.... Read more

    Affected Products : ident2
    • EPSS Score: %3.42
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1052

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.... Read more

    Affected Products : db2 db2_universal_database
    • EPSS Score: %0.37
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0692

    The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.... Read more

    Affected Products : qt
    • EPSS Score: %2.24
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0642

    Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.... Read more

    • EPSS Score: %25.80
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1698

    The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash... Read more

    Affected Products : popmessenger
    • EPSS Score: %5.89
    • Published: Sep. 24, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1378

    The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket th... Read more

    Affected Products : jabberd jadc2s
    • EPSS Score: %2.93
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1694

    Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.... Read more

    Affected Products : on_command_ccm on_icommand
    • EPSS Score: %1.36
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1699

    SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.... Read more

    Affected Products : showcenter
    • EPSS Score: %9.68
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1697

    The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.... Read more

    Affected Products : unicenter_management
    • EPSS Score: %0.74
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1696

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.... Read more

    Affected Products : server4
    • EPSS Score: %1.95
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 292628 Results