Latest CVE Feed
-
2.1
LOWCVE-2004-0133
The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more
Affected Products : linux_kernel- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0177
The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions... Read more
Affected Products : linux_kernel- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0387
Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0117
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0119
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit r... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0197
Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.... Read more
Affected Products : jet- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0123
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_nt windows_98se windows_me- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0391
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0533
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Wind... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_nt windows_me netmeeting- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0409
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.... Read more
Affected Products : xchat- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0807
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted reques... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0663
Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.... Read more
Affected Products : windows_2000- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0156
Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : ssmtp- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0910
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor ... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2044
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which all... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0385
Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the outp... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0403
Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2003-0906
Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF im... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0907
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2041
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : e107- Published: May. 29, 2004
- Modified: Apr. 03, 2025