Latest CVE Feed
-
6.4
MEDIUMCVE-2004-0723
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."... Read more
Affected Products : java_virtual_machine- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0741
LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.... Read more
Affected Products : www_file_share_pro- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0742
Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.... Read more
Affected Products : java_system_calendar_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0708
MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0720
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.... Read more
Affected Products : safari- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0700
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HT... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0706
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0725
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.... Read more
Affected Products : moodle- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2004-0698
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0714
Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory co... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-2061
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0736
The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0566
Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.... Read more
Affected Products : internet_explorer- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0696
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.... Read more
Affected Products : webstar- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0595
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and... Read more
Affected Products : php fedora_core secure_linux converged_communications_server s8300 s8500 s8700 integrated_management- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0705
Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow r... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0731
Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.... Read more
Affected Products : php-nuke- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0632
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that is not normally handled by Reader, triggering a buffer ... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1048
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.... Read more
Affected Products : internet_explorer outlook windows_server_2003 windows_xp windows_98 windows_nt windows_98se windows_me- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0715
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members ... Read more
Affected Products : weblogic_server- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025