Latest CVE Feed
-
10.0
HIGHCVE-2004-0333
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0311
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : ap9606- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0270
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling progr... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0079
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop ios openssl hp-ux freebsd mac_os_x mac_os_x_server imanager bsafe_ssl-j +56 more products- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0348
SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.... Read more
Affected Products : spidersales- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0598
The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.... Read more
Affected Products : libpng- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0743
Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward or backward buttons, which may cause an information leak.... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0256
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.... Read more
Affected Products : libtool- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0284
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0262
Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.... Read more
Affected Products : the_palace_client- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0361
The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.... Read more
Affected Products : safari- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0298
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.... Read more
Affected Products : cesarftp- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0266
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.... Read more
Affected Products : php-nuke- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0275
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.... Read more
Affected Products : bosdates- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0310
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.... Read more
Affected Products : livejournal- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0286
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.... Read more
Affected Products : robotftp_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0337
Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bu... Read more
Affected Products : 602pro_lan_suite- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.... Read more
- Published: Nov. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1315
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special char... Read more
Affected Products : phpbb- Published: Nov. 12, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0958
php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.... Read more
Affected Products : php- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025