Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2004-2005

    Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.... Read more

    Affected Products : eudora
    • Published: May. 06, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-2004

    The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.... Read more

    Affected Products : suse_linux
    • Published: May. 06, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-2002

    Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.... Read more

    Affected Products : irix
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1998

    The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.... Read more

    Affected Products : php-nuke
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2000

    SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.... Read more

    Affected Products : php-nuke
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1999

    Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.... Read more

    Affected Products : php-nuke
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-1997

    Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.... Read more

    Affected Products : kolab_groupware_server openpkg
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-1994

    FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.... Read more

    Affected Products : fusetalk
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1996

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.... Read more

    Affected Products : smf
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-2001

    ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.... Read more

    Affected Products : irix
    • Published: May. 05, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0648

    Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.... Read more

    Affected Products : debian_linux fte_text_editor
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0618

    Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.... Read more

    Affected Products : debian_linux suidperl
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0781

    Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.... Read more

    Affected Products : ecartis
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0782

    Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.... Read more

    Affected Products : ecartis
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0382

    Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.... Read more

    Affected Products : mac_os_x mac_os_x
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0366

    SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.... Read more

    Affected Products : pam-pgsql
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0368

    Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.... Read more

    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0370

    The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.... Read more

    Affected Products : freebsd
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0367

    Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.... Read more

    Affected Products : ethereal
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0365

    The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.... Read more

    Affected Products : ethereal
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 293622 Results