Latest CVE Feed
-
2.1
LOWCVE-2004-0511
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.... Read more
Affected Products : openserver- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0564
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0998
Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0601
distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.... Read more
Affected Products : distcc- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0803
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop mac_os_x mac_os_x_server libtiff suse_linux linux_advanced_workstation mandrake_linux fedora_core secure_linux +3 more products- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0441
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a cr... Read more
Affected Products : adaptive_server_enterprise- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0066
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number ... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0067
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated usi... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0068
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blin... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1778
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.... Read more
Affected Products : skype- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0452
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink at... Read more
Affected Products : perl- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be alloca... Read more
Affected Products : solaris sunos mac_os_x mac_os_x_server libtiff unixware modular_messaging_message_storage_server propack linux linux +10 more products- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0852
Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.... Read more
Affected Products : htget- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1329
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a... Read more
Affected Products : aix- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1326
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.... Read more
Affected Products : dxterm- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1374
Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.... Read more
Affected Products : netbsd- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1324
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.... Read more
- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1325
The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local... Read more
- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1768
The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized... Read more
Affected Products : brightmail_antispam- Published: Dec. 17, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1323
Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.... Read more
Affected Products : netbsd- Published: Dec. 16, 2004
- Modified: Apr. 03, 2025