Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1739
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.... Read more
Affected Products : internet_chat_server- Published: Aug. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1740
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.... Read more
Affected Products : music_daemon- Published: Aug. 23, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1735
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : sympa- Published: Aug. 21, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1727
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.... Read more
Affected Products : badblue- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1733
Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.... Read more
Affected Products : mydms- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1731
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.... Read more
Affected Products : mantis- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1729
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.... Read more
Affected Products : web_log_analyzer- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1732
SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.... Read more
Affected Products : mydms- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1726
Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.... Read more
Affected Products : xv- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1728
Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.... Read more
Affected Products : sara- Published: Aug. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0490
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which all... Read more
Affected Products : cpanel- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0487
A certain ActiveX control in Symantec Norton AntiVirus 2004 allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary programs.... Read more
Affected Products : norton_antivirus- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0722
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0766
NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.... Read more
Affected Products : stackdefender- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1045
votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modif... Read more
Affected Products : bugzilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1044
editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group t... Read more
Affected Products : bugzilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0503
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting ... Read more
Affected Products : outlook- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0425
Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.... Read more
Affected Products : sideminder_affiliate_agent- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0514
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0505
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025