Latest CVE Feed
-
7.5
HIGHCVE-2004-1826
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : mambo_open_source_4.5- Published: Mar. 16, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1825
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.... Read more
Affected Products : mambo_open_source- Published: Mar. 16, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0168
Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0189
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access co... Read more
Affected Products : squid- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0094
Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1822
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target p... Read more
Affected Products : phorum- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1816
Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1827
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1819
4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.... Read more
Affected Products : 4nalbum_module- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0169
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.... Read more
Affected Products : darwin_streaming_server- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0190
Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.... Read more
Affected Products : firewall_vpn_appliance_100 firewall_vpn_appliance_200 firewall_vpn_appliance_200r- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0186
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0191
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using o... Read more
Affected Products : mozilla- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0171
FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from ... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0167
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0166
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0093
XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0172
Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a ... Read more
Affected Products : ltrace- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0192
Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the result... Read more
Affected Products : gateway_security_5400- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0075
The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.... Read more
Affected Products : linux_kernel- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025