Latest CVE Feed
-
2.1
LOWCVE-2004-0178
The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of b... Read more
Affected Products : linux_kernel- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0182
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.... Read more
Affected Products : mailman- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0124
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0157
x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.... Read more
Affected Products : xonix- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0405
CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.... Read more
Affected Products : cvs- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0663
Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.... Read more
Affected Products : windows_2000- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0180
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.... Read more
Affected Products : cvs- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0120
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0910
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor ... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2040
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg p... Read more
Affected Products : e107- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2042
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.... Read more
Affected Products : e107- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2038
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.... Read more
Affected Products : land_down_under- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2041
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : e107- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2039
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error mes... Read more
Affected Products : e107- Published: May. 29, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2036
SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.... Read more
Affected Products : jportal_web_portal- Published: May. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2035
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.... Read more
Affected Products : minimal_http_server- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2135
cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.... Read more
Affected Products : linux_kernel- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2033
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.... Read more
Affected Products : orenosv_http_ftp_server- Published: May. 26, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2032
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.... Read more
Affected Products : rp114- Published: May. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2029
The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.... Read more
Affected Products : bnbt- Published: May. 22, 2004
- Modified: Apr. 03, 2025