Latest CVE Feed
-
7.5
HIGHCVE-2004-0127
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0009
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.... Read more
Affected Products : apache-ssl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0010
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0083
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-200... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0129
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.... Read more
Affected Products : phpmyadmin- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1575
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email messa... Read more
Affected Products : cgiemail- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0987
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.... Read more
Affected Products : http_server- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0991
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0039
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0006
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo lo... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0818
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0088
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0130
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error mes... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0086
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0103
crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.... Read more
Affected Products : crawl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0143
Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.... Read more
Affected Products : 6310i- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0092
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0128
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2003-0825
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1990
Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.... Read more
Affected Products : aldos_web_server- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025