Latest CVE Feed
-
3.6
LOWCVE-2004-0435
Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to ... Read more
Affected Products : freebsd- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0230
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use lo... Read more
Affected Products : junos windows_2000 windows_server_2003 windows_xp solaris network_data_loss_prevention netbsd windows_98 windows_98se openpgp +2 more products- Published: Aug. 18, 2004
- Modified: May. 02, 2025
-
5.0
MEDIUMCVE-2004-0232
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0765
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote a... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0519
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compo... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0523
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1724
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable ... Read more
Affected Products : php_fusion- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0631
Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is... Read more
Affected Products : acrobat_reader- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0762
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0506
The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0507
Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0234
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA arch... Read more
Affected Products : winzip f-secure_anti-virus internet_gatekeeper f-secure_internet_security winrar propack fedora_core f-secure_personal_express mailsweeper f-secure_for_firewalls +3 more products- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0518
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0517
Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0516
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0476
Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.... Read more
Affected Products : 3cp4144- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0421
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0419
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1042
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.... Read more
Affected Products : bugzilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0757
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025