Latest CVE Feed
-
10.0
HIGHCVE-2003-0648
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0218
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0374
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.... Read more
Affected Products : interchange- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1993
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.... Read more
Affected Products : omail_webmail- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0149
Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.... Read more
Affected Products : xboing- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0184
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, wh... Read more
Affected Products : tcpdump- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0367
Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.... Read more
Affected Products : ethereal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0370
The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.... Read more
Affected Products : freebsd- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0366
SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.... Read more
Affected Products : pam-pgsql- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0368
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0382
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0371
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.... Read more
Affected Products : heimdal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0365
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.... Read more
Affected Products : ethereal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0219
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0618
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0428
Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown impact.... Read more
- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1982
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.... Read more
Affected Products : yabb- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1991
Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.... Read more
Affected Products : aldo\'s_web_server- Published: May. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1983
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1981
The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025