Latest CVE Feed
-
4.6
MEDIUMCVE-2003-1049
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.... Read more
Affected Products : db2_universal_database- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0699
Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed A... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0928
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.... Read more
Affected Products : mailsweeper- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0745
LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.... Read more
Affected Products : lha- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0558
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.... Read more
Affected Products : cups- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0931
Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.... Read more
Affected Products : enforcer- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1051
Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.... Read more
Affected Products : db2- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0163
Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.... Read more
Affected Products : secure_enterprise- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0629
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.... Read more
- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0693
The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.... Read more
Affected Products : qt- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0929
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.... Read more
Affected Products : mailsweeper- Published: Sep. 28, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1698
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash... Read more
Affected Products : popmessenger- Published: Sep. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1378
The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket th... Read more
- Published: Sep. 21, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1696
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.... Read more
Affected Products : server4- Published: Sep. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1697
The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.... Read more
Affected Products : unicenter_management- Published: Sep. 21, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1694
Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.... Read more
- Published: Sep. 21, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1699
SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.... Read more
Affected Products : showcenter- Published: Sep. 21, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1695
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).... Read more
Affected Products : server4- Published: Sep. 20, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1691
The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.... Read more
Affected Products : dns4me- Published: Sep. 18, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1690
Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.... Read more
Affected Products : dns4me- Published: Sep. 18, 2004
- Modified: Apr. 03, 2025