Latest CVE Feed
-
2.1
LOWCVE-2004-0381
mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0183
TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Sui... Read more
Affected Products : tcpdump- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0174
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening so... Read more
Affected Products : http_server- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0781
Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.... Read more
Affected Products : ecartis- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0374
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.... Read more
Affected Products : interchange- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0428
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.... Read more
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1982
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.... Read more
Affected Products : yabb- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1991
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more
Affected Products : aldo\'s_web_server- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1984
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, wh... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1983
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1981
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2043
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using ... Read more
- Published: May. 01, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1985
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1979
Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.... Read more
Affected Products : props- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1989
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.i... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1980
Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.... Read more
Affected Products : props- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1987
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1978
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.... Read more
Affected Products : moodle- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1988
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1977
3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.... Read more
Affected Products : webbngss3nbxnts- Published: Apr. 29, 2004
- Modified: Apr. 03, 2025