Latest CVE Feed
-
7.5
HIGHCVE-2004-0688
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malfo... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0794
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0750
Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0768
libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
Affected Products : libpng3- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0793
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.... Read more
Affected Products : bsdmainutils- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0752
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.... Read more
Affected Products : openoffice- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0799
The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0796
SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.... Read more
Affected Products : spamassassin- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0753
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0785
Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0775
Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitr... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1380
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing ... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0777
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.... Read more
Affected Products : courier-imap- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1015
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0754
Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.... Read more
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0792
Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.... Read more
Affected Products : rsync- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0778
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.... Read more
Affected Products : cvs- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0755
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.... Read more
Affected Products : ruby- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025