Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-0038

    McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.... Read more

    Affected Products : epolicy_orchestrator
    • Published: Jun. 14, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1580

    Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.... Read more

    Affected Products : cyrus_imap_server
    • Published: Jun. 14, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0396

    Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.... Read more

    Affected Products : cvs
    • Published: Jun. 14, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0910

    The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor ... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0409

    Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.... Read more

    Affected Products : xchat
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0807

    Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted reques... Read more

    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2003-0907

    Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.... Read more

    Affected Products : windows_server_2003 windows_xp
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0157

    x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.... Read more

    Affected Products : xonix
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0405

    CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.... Read more

    Affected Products : cvs
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0118

    The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0155

    The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middl... Read more

    Affected Products : enterprise_linux racoon
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0116

    An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.... Read more

    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0806

    Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.... Read more

    Affected Products : windows_2000 windows_xp windows_nt
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0182

    Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.... Read more

    Affected Products : mailman
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0178

    The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of b... Read more

    Affected Products : linux_kernel
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2004-0124

    The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."... Read more

    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0388

    The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.... Read more

    Affected Products : mysql
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2004-0407

    The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before t... Read more

    Affected Products : coldfusion
    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0385

    Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vaguen... Read more

    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-2044

    PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which all... Read more

    • Published: Jun. 01, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 294326 Results