Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1705
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.... Read more
Affected Products : ux- Published: Jul. 30, 2004
- Modified: Apr. 03, 2025
-
8.8
HIGHCVE-2004-1703
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page... Read more
Affected Products : fusion_news- Published: Jul. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1704
WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.... Read more
Affected Products : wpquiz- Published: Jul. 30, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1707
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privi... Read more
Affected Products : application_server database_server_lite oracle8i oracle9i application_server_portal- Published: Jul. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2066
SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.... Read more
Affected Products : linpha- Published: Jul. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2067
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.... Read more
Affected Products : jaws- Published: Jul. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2064
Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.... Read more
Affected Products : lostbook- Published: Jul. 29, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0723
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."... Read more
Affected Products : java_virtual_machine- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0736
The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0715
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members ... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0711
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0704
Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0728
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory addre... Read more
Affected Products : systems_management_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0739
Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.... Read more
Affected Products : whisper_ftp_surfer- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0730
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parameter in lang_faq.php as accessible from faq.php, or (3) t... Read more
Affected Products : phpbb- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0740
The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.... Read more
Affected Products : t522_network_printer- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0703
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0595
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and... Read more
Affected Products : php fedora_core secure_linux converged_communications_server s8300 s8500 s8700 integrated_management- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0696
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0594
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the ... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025