Latest CVE Feed
-
5.0
MEDIUMCVE-2004-0944
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.... Read more
Affected Products : mitel_3300_integrated_communication_platform- Published: Feb. 28, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1360
Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.... Read more
- Published: Feb. 27, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0322
Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php... Read more
Affected Products : xmb- Published: Feb. 23, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0324
Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.... Read more
Affected Products : confirm- Published: Feb. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0466
WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.... Read more
Affected Products : webconnect- Published: Feb. 21, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2136
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.... Read more
Affected Products : linux_kernel- Published: Feb. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0064
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.... Read more
Affected Products : suse_linux- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0049
Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.... Read more
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0061
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.... Read more
Affected Products : www_file_share_pro- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0063
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by acceptin... Read more
Affected Products : payshield_spp_library- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0001
Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.... Read more
Affected Products : linux_kernel- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0054
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 pro... Read more
Affected Products : ios- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-0091
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. ... Read more
Affected Products : vbulletin- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0700
The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-... Read more
Affected Products : kernel- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0074
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.... Read more
Affected Products : xsok- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0055
The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.... Read more
Affected Products : tcpdump- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0069
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.... Read more
Affected Products : windows_ftp_server- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0059
Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.... Read more
Affected Products : www_file_share_pro- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0068
PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : phpdig- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0056
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service an... Read more
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025