Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2004-0122

    Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.... Read more

    Affected Products : msn_messenger
    • EPSS Score: %32.96
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-1040

    kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.08
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0362

    Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI respon... Read more

    • EPSS Score: %83.40
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0363

    Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method... Read more

    Affected Products : norton_antispam
    • EPSS Score: %72.68
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1033

    The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via ... Read more

    Affected Products : sap_db
    • EPSS Score: %0.04
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1577

    SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.... Read more

    Affected Products : sap_r_3
    • EPSS Score: %0.64
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1934

    PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.... Read more

    Affected Products : gemitel
    • EPSS Score: %7.57
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0372

    xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.... Read more

    Affected Products : xine
    • EPSS Score: %0.10
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1936

    ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.... Read more

    Affected Products : zonealarm
    • EPSS Score: %0.36
    • Published: Apr. 14, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1944

    Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.... Read more

    Affected Products : eudora
    • EPSS Score: %3.92
    • Published: Apr. 14, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1939

    Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.... Read more

    Affected Products : zaep_antispam
    • EPSS Score: %0.88
    • Published: Apr. 14, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-1758

    BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %0.12
    • Published: Apr. 13, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1929

    SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.... Read more

    Affected Products : php-nuke
    • EPSS Score: %0.13
    • Published: Apr. 13, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1756

    BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other user... Read more

    Affected Products : weblogic_server
    • EPSS Score: %1.80
    • Published: Apr. 13, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1932

    SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.... Read more

    Affected Products : php-nuke
    • EPSS Score: %0.02
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-1933

    Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.... Read more

    Affected Products : ux
    • EPSS Score: %0.07
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1930

    Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.... Read more

    Affected Products : php-nuke
    • EPSS Score: %0.17
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1060

    Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Se... Read more

    Affected Products : tcp icmp
    • EPSS Score: %59.91
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1925

    Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ran... Read more

    Affected Products : tikiwiki_cms\/groupware
    • EPSS Score: %0.42
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1928

    The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.... Read more

    Affected Products : tikiwiki_cms\/groupware
    • EPSS Score: %6.84
    • Published: Apr. 12, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 292323 Results