Latest CVE Feed
-
7.5
HIGHCVE-2004-0737
Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (1... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0732
SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0686
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0729
PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.... Read more
Affected Products : phpbb- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0717
Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0702
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0711
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote attackers to bypass intended access restrictions because... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0715
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members ... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-2061
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0695
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0594
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the ... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0728
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory addre... Read more
Affected Products : systems_management_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0726
The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.... Read more
Affected Products : windows_2000- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0734
Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.... Read more
Affected Products : extropia_webstore- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0703
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0701
Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to g... Read more
Affected Products : ray_server_software- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0733
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.... Read more
Affected Products : ollydbg- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0719
Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and ot... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0724
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0721
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerab... Read more
Affected Products : konqueror- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025