Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1604
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.... Read more
Affected Products : cpanel- Published: Sep. 30, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0190
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ?... Read more
- Published: Sep. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0629
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0500
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy ca... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0691
Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.... Read more
Affected Products : qt- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0745
LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.... Read more
Affected Products : lha- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0644
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.... Read more
Affected Products : kerberos_5- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0457
The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mysql- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0458
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0643
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0593
Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0928
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.... Read more
Affected Products : mailsweeper- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1049
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.... Read more
Affected Products : db2_universal_database- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0699
Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed A... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1050
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.... Read more
Affected Products : db2- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2004-0689
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0573
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0690
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0558
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.... Read more
Affected Products : cups- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1052
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025