Latest CVE Feed
-
2.1
LOWCVE-2004-1834
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.... Read more
Affected Products : http_server- Published: Mar. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1853
Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.... Read more
Affected Products : terminator_3_war_of_the_machines- Published: Mar. 19, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1829
Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the ... Read more
Affected Products : php-nuke_module- Published: Mar. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1830
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.... Read more
Affected Products : php-nuke- Published: Mar. 18, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1825
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.... Read more
Affected Products : mambo_open_source- Published: Mar. 16, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1826
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : mambo_open_source_4.5- Published: Mar. 16, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1818
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0159
Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.... Read more
Affected Products : hsftp- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0172
Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a ... Read more
Affected Products : ltrace- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0093
XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0167
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0166
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0165
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0075
The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.... Read more
Affected Products : linux_kernel- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0094
Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1821
SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0188
Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.... Read more
Affected Products : calife- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0110
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1819
4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1822
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target p... Read more
Affected Products : phorum- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025