Latest CVE Feed
-
7.5
HIGHCVE-2004-0718
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attac... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0705
Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow r... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0696
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0595
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and... Read more
Affected Products : php fedora_core secure_linux converged_communications_server s8300 s8500 s8700 integrated_management- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0712
The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0686
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0702
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0732
SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0717
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0729
PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.... Read more
Affected Products : phpbb- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0737
Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (1... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0735
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such... Read more
Affected Products : medal_of_honor_allied_assault- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0727
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to anot... Read more
Affected Products : internet_explorer- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0723
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."... Read more
Affected Products : java_virtual_machine- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0741
LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.... Read more
Affected Products : www_file_share_pro- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0714
Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory co... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0700
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HT... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0695
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0594
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the ... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-2061
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025