Latest CVE Feed
-
7.5
HIGHCVE-2004-0779
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to ... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0760
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.... Read more
Affected Products : mozilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0519
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compo... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0394
A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.... Read more
Affected Products : linux_kernel- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0233
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0513
Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0764
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0761
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0520
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0193
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").... Read more
Affected Products : catdoc- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0476
Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.... Read more
Affected Products : 3cp4144- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0504
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0421
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0419
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0515
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0502
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictab... Read more
Affected Products : outlook- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0501
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, wh... Read more
Affected Products : outlook- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1043
SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.... Read more
Affected Products : bugzilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1046
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.... Read more
Affected Products : bugzilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0630
The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of th... Read more
Affected Products : acrobat_reader- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025