Latest CVE Feed
-
6.8
MEDIUMCVE-2004-0339
Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0344
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.... Read more
Affected Products : yabb- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0359
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.... Read more
Affected Products : invision_board- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0599
Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application... Read more
Affected Products : libpng- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0343
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.... Read more
Affected Products : yabb- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0355
Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.... Read more
Affected Products : invision_board- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0330
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.... Read more
Affected Products : serv-u_file_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0356
Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.... Read more
Affected Products : slmail_pro- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0335
LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.... Read more
Affected Products : 602pro_lan_suite- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0597
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency ... Read more
Affected Products : windows_media_player windows_messenger windows_98se windows_me msn_messenger libpng- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0329
FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".... Read more
Affected Products : freechat- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0744
The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger p... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0771
Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any... Read more
Affected Products : lha- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0270
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling progr... Read more
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0112
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a craft... Read more
Affected Products : enterprise_linux enterprise_linux_desktop ios openssl hp-ux freebsd mac_os_x mac_os_x_server imanager bsafe_ssl-j +55 more products- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0203
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.... Read more
Affected Products : exchange_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0286
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.... Read more
Affected Products : robotftp_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0337
Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bu... Read more
Affected Products : 602pro_lan_suite- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0272
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.... Read more
Affected Products : maxwebportal- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0310
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.... Read more
Affected Products : livejournal- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025