Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1990
Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.... Read more
Affected Products : aldos_web_server- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0105
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0040
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0164
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0078
Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.... Read more
Affected Products : mutt- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0115
VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.... Read more
Affected Products : virtual_pc- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0082
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password... Read more
Affected Products : samba- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0106
Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0097
Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.... Read more
Affected Products : pwlib- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0087
The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1574
Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors.... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0131
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which ... Read more
Affected Products : radius- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0006
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo lo... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0818
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0085
Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0114
The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, whic... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1575
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email messa... Read more
Affected Products : cgiemail- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0132
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[languag... Read more
Affected Products : ezcontents- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0084
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a differ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0991
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025