Latest CVE Feed
-
4.3
MEDIUMCVE-2004-1632
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.... Read more
Affected Products : moniwiki- Published: Oct. 25, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1635
Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remot... Read more
Affected Products : bugzilla- Published: Oct. 24, 2004
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2004-1628
Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.... Read more
Affected Products : rssh- Published: Oct. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1629
Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.... Read more
Affected Products : dwc_articles- Published: Oct. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1626
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.... Read more
Affected Products : ability_server- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1627
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.... Read more
Affected Products : ability_server- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1625
pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.... Read more
Affected Products : pgina- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1623
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.... Read more
Affected Products : windows_xp- Published: Oct. 22, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1624
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button... Read more
Affected Products : carbon_copy- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1620
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer f... Read more
Affected Products : serendipity- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1622
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.... Read more
Affected Products : ubb.threads- Published: Oct. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0161
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1016
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplic... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0778
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.... Read more
Affected Products : cvs- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0785
Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0748
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.... Read more
Affected Products : http_server- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0784
The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0775
Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitr... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-0772
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0793
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more
Affected Products : bsdmainutils- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025