Latest CVE Feed
-
9.8
CRITICALCVE-2004-2061
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0700
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HT... Read more
- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-2053
PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.... Read more
Affected Products : easyins- Published: Jul. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2051
The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.... Read more
Affected Products : thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs- Published: Jul. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2047
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.... Read more
Affected Products : easyweb_filemanager- Published: Jul. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1749
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.... Read more
Affected Products : attack_mitigator- Published: Jul. 22, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2055
Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.... Read more
Affected Products : phpbb- Published: Jul. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0423
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.... Read more
Affected Products : ssmtp- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0424
Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0475
The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this ... Read more
Affected Products : ie- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0483
Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.... Read more
Affected Products : irix- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0485
The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0427
The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local use... Read more
Affected Products : linux_kernel- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0470
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not ... Read more
Affected Products : weblogic_server- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0474
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable t... Read more
Affected Products : windows_xp- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0437
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an inva... Read more
Affected Products : titan_ftp_server- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0422
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0431
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.... Read more
Affected Products : quicktime- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0401
Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.... Read more
Affected Products : libtasn1- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0473
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-... Read more
Affected Products : opera_browser- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025