Latest CVE Feed
-
1.2
LOWCVE-2004-0404
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.... Read more
Affected Products : logcheck- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0444
Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow re... Read more
Affected Products : client_security norton_internet_security norton_antispam norton_personal_firewall client_firewall- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0484
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after t... Read more
Affected Products : internet_explorer- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2004-0489
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0482
Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0401
Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.... Read more
Affected Products : libtasn1- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1345
Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access.... Read more
- Published: Jun. 21, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1346
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.... Read more
Affected Products : solaris- Published: Jun. 19, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1754
The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.... Read more
- Published: Jun. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0154
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.... Read more
Affected Products : nfs-utils- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0199
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvd... Read more
- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0392
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" f... Read more
Affected Products : racoon- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1580
Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.... Read more
Affected Products : cyrus_imap_server- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0050
Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.... Read more
Affected Products : ultraseek- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0227
Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.... Read more
Affected Products : zoneminder- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1041
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does ... Read more
- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0396
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.... Read more
Affected Products : cvs- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0038
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.... Read more
Affected Products : epolicy_orchestrator- Published: Jun. 14, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0117
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0405
CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.... Read more
Affected Products : cvs- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025