Latest CVE Feed
-
7.5
HIGHCVE-2004-0104
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0077
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local user... Read more
Affected Products : linux_kernel secure_linux kernel bigmem_kernel kernel_doc kernel_source netwosix_linux- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2003-0825
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0040
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0082
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password... Read more
Affected Products : samba- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0106
Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0039
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0132
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[languag... Read more
Affected Products : ezcontents- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0128
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0130
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error mes... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1990
Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.... Read more
Affected Products : aldos_web_server- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0084
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a differ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0991
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0009
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.... Read more
Affected Products : apache-ssl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0099
mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended ac... Read more
Affected Products : freebsd- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0003
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0127
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0089
Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0080
The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.... Read more
Affected Products : util-linux- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0010
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025