Latest CVE Feed
-
7.5
HIGHCVE-2004-0867
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was la... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0833
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.... Read more
Affected Products : debian_linux- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0834
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0842
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0510
Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.... Read more
Affected Products : openserver- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0564
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0998
Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0601
distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.... Read more
Affected Products : distcc- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0816
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.... Read more
Affected Products : linux_kernel- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0749
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and oth... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2004-1339
SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1375
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.... Read more
Affected Products : hp-ux- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0511
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.... Read more
Affected Products : openserver- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2004-1338
The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then per... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1336
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1373
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.... Read more
Affected Products : shoutcast_server- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0805
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0810
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.... Read more
Affected Products : timbuktu_pro_mac- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0875
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.... Read more
Affected Products : phpgroupware- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0841
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025