Latest CVE Feed
-
7.2
HIGHCVE-2004-1337
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0833
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.... Read more
Affected Products : debian_linux- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2004-1339
SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0749
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and oth... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0563
The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a username and password.... Read more
Affected Products : freenet6- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0816
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.... Read more
Affected Products : linux_kernel- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0510
Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.... Read more
Affected Products : openserver- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0875
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.... Read more
Affected Products : phpgroupware- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0564
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0998
Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0601
distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.... Read more
Affected Products : distcc- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0441
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a cr... Read more
Affected Products : adaptive_server_enterprise- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0067
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated usi... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0068
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blin... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1778
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.... Read more
Affected Products : skype- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0066
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number ... Read more
Affected Products : tcp- Published: Dec. 22, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be alloca... Read more
Affected Products : solaris sunos mac_os_x mac_os_x_server libtiff unixware modular_messaging_message_storage_server propack linux linux +10 more products- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0452
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink at... Read more
Affected Products : perl- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1329
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a... Read more
Affected Products : aix- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1326
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.... Read more
Affected Products : dxterm- Published: Dec. 20, 2004
- Modified: Apr. 03, 2025