Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2004-0690

    The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.... Read more

    Affected Products : kde kde
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0930

    Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.... Read more

    Affected Products : mailsweeper
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0558

    The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.... Read more

    Affected Products : cups
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0629

    Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.... Read more

    Affected Products : acrobat acrobat_reader
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1052

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.... Read more

    Affected Products : db2 db2_universal_database
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 7.1

    HIGH
    CVE-2004-0689

    KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.... Read more

    Affected Products : debian_linux kde
    • Published: Sep. 28, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1698

    The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash... Read more

    Affected Products : popmessenger
    • Published: Sep. 24, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1378

    The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket th... Read more

    Affected Products : jabberd jadc2s
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1694

    Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.... Read more

    Affected Products : on_command_ccm on_icommand
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1699

    SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.... Read more

    Affected Products : showcenter
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1696

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.... Read more

    Affected Products : server4
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1697

    The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.... Read more

    Affected Products : unicenter_management
    • Published: Sep. 21, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1695

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).... Read more

    Affected Products : server4
    • Published: Sep. 20, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1692

    Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.... Read more

    Affected Products : mambo_open_source
    • Published: Sep. 18, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-1693

    PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.... Read more

    Affected Products : mambo
    • Published: Sep. 18, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1691

    The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.... Read more

    Affected Products : dns4me
    • Published: Sep. 18, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1690

    Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.... Read more

    Affected Products : dns4me
    • Published: Sep. 18, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-0534

    Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.... Read more

    Affected Products : webintelligence infoview
    • Published: Sep. 17, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1687

    CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.... Read more

    Affected Products : snitz_forums_2000
    • Published: Sep. 16, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0866

    Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.... Read more

    • Published: Sep. 16, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 293360 Results