Latest CVE Feed
-
10.0
HIGHCVE-2004-1993
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.... Read more
Affected Products : omail_webmail- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0383
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0376
oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.... Read more
Affected Products : oftpd- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0377
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0386
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0380
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file... Read more
Affected Products : outlook_express- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0379
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.... Read more
Affected Products : sharepoint_portal_server- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0219
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0428
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.... Read more
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1991
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more
Affected Products : aldo\'s_web_server- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1982
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.... Read more
Affected Products : yabb- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1984
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, wh... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1981
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1983
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2043
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using ... Read more
- Published: May. 01, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1987
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1980
Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.... Read more
Affected Products : props- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1989
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.i... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1979
Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.... Read more
Affected Products : props- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1985
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.... Read more
- Published: Apr. 30, 2004
- Modified: Apr. 03, 2025