Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0165
Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0191
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using o... Read more
Affected Products : mozilla- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0186
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0192
Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the result... Read more
Affected Products : gateway_security_5400- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0167
DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0172
Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a ... Read more
Affected Products : ltrace- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0166
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1822
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target p... Read more
Affected Products : phorum- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0171
FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from ... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0190
Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.... Read more
Affected Products : firewall_vpn_appliance_100 firewall_vpn_appliance_200 firewall_vpn_appliance_200r- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0093
XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0169
QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.... Read more
Affected Products : darwin_streaming_server- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1815
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0110
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.... Read more
- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0188
Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.... Read more
Affected Products : calife- Published: Mar. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1358
The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.... Read more
Affected Products : solaris- Published: Mar. 12, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1199
Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : myproxy- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1770
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1769
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.... Read more
- Published: Mar. 04, 2004
- Modified: Apr. 03, 2025