Latest CVE Feed
-
7.5
HIGHCVE-2004-2003
Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.... Read more
Affected Products : delegate- Published: May. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-2004
The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.... Read more
Affected Products : suse_linux- Published: May. 06, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-2005
Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.... Read more
Affected Products : eudora- Published: May. 06, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1998
The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.... Read more
Affected Products : php-nuke- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2002
Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.... Read more
Affected Products : irix- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1999
Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.... Read more
Affected Products : php-nuke- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2000
SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.... Read more
Affected Products : php-nuke- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1997
Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.... Read more
- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1994
FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.... Read more
Affected Products : fusetalk- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-2001
ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.... Read more
Affected Products : irix- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1996
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.... Read more
Affected Products : smf- Published: May. 05, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0365
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.... Read more
Affected Products : ethereal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0366
SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.... Read more
Affected Products : pam-pgsql- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0368
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0367
Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.... Read more
Affected Products : ethereal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0370
The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.... Read more
Affected Products : freebsd- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0371
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.... Read more
Affected Products : heimdal- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0382
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0221
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0222
Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025