Latest CVE Feed
-
10.0
HIGHCVE-2004-0300
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.p... Read more
Affected Products : store_kit- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2004-0258
Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0293
Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.... Read more
Affected Products : shopcartcgi- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0321
Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.... Read more
Affected Products : team_factor- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0313
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.... Read more
Affected Products : psoproxy_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0276
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.... Read more
Affected Products : monkey- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0329
FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".... Read more
Affected Products : freechat- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0291
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.... Read more
Affected Products : yabb- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0304
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.... Read more
Affected Products : webstores_2000- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0306
Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in ... Read more
Affected Products : optical_networking_systems_software- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0346
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.... Read more
Affected Products : proftpd- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0287
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.... Read more
Affected Products : xlight_ftp_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0334
InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOT... Read more
Affected Products : innomedia_videophone- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0357
Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.... Read more
Affected Products : slmail_pro- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0354
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in... Read more
Affected Products : anubis- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0332
Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.... Read more
Affected Products : extremail- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0494
Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0081
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop ios openssl hp-ux freebsd mac_os_x mac_os_x_server imanager bsafe_ssl-j +56 more products- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0079
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop ios openssl hp-ux freebsd mac_os_x mac_os_x_server imanager bsafe_ssl-j +56 more products- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.... Read more
- Published: Nov. 16, 2004
- Modified: Apr. 03, 2025