Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0788
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0746
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0747
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.... Read more
Affected Products : http_server- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0768
libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
Affected Products : libpng3- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0799
The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0162
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0793
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more
Affected Products : bsdmainutils- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0752
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.... Read more
Affected Products : openoffice- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0796
SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.... Read more
Affected Products : spamassassin- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0051
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0052
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, o... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0785
Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0784
The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0753
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1353
Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.... Read more
- Published: Oct. 19, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1618
Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.... Read more
Affected Products : tonecast- Published: Oct. 19, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1608
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.... Read more
- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1612
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.... Read more
Affected Products : saleslogix- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1616
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.... Read more
Affected Products : links- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025