Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0799
The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0768
libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
Affected Products : libpng3- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0796
SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.... Read more
Affected Products : spamassassin- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0793
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more
Affected Products : bsdmainutils- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0748
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.... Read more
Affected Products : http_server- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0162
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0051
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0688
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malfo... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0753
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0783
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0161
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0755
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.... Read more
Affected Products : ruby- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1015
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0777
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.... Read more
Affected Products : courier-imap- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1380
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing ... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1353
Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.... Read more
- Published: Oct. 19, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1618
Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.... Read more
Affected Products : tonecast- Published: Oct. 19, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1612
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.... Read more
Affected Products : saleslogix- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1616
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.... Read more
Affected Products : links- Published: Oct. 18, 2004
- Modified: Apr. 03, 2025