Latest CVE Feed
-
7.2
HIGHCVE-2004-0834
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0833
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.... Read more
Affected Products : debian_linux- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1336
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0749
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and oth... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1375
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.... Read more
Affected Products : hp-ux- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0816
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.... Read more
Affected Products : linux_kernel- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0685
Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0841
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0810
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.... Read more
Affected Products : timbuktu_pro_mac- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1778
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.... Read more
Affected Products : skype- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0066
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number ... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0067
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated usi... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0068
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blin... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0441
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a cr... Read more
Affected Products : adaptive_server_enterprise- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be alloca... Read more
Affected Products : solaris sunos mac_os_x mac_os_x_server libtiff unixware modular_messaging_message_storage_server propack linux linux +10 more products- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0452
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink at... Read more
Affected Products : perl- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0852
Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.... Read more
Affected Products : htget- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1326
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.... Read more
Affected Products : dxterm- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1329
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a... Read more
Affected Products : aix- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1324
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.... Read more
- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025