Latest CVE Feed
-
4.3
MEDIUMCVE-2004-1825
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.... Read more
Affected Products : mambo_open_source- Published: Mar. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0193
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, B... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0189
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access co... Read more
Affected Products : squid- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1818
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0094
Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0168
Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0185
Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.... Read more
Affected Products : wu-ftpd- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1816
Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1819
4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0191
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using o... Read more
Affected Products : mozilla- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0190
Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.... Read more
Affected Products : firewall_vpn_appliance_100 firewall_vpn_appliance_200 firewall_vpn_appliance_200r- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0186
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0169
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.... Read more
Affected Products : darwin_streaming_server- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0171
FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from ... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1822
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target p... Read more
Affected Products : phorum- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1827
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0192
Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the result... Read more
Affected Products : gateway_security_5400- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1821
SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0165
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0159
Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.... Read more
Affected Products : hsftp- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025