Latest CVE Feed
-
7.5
HIGHCVE-2004-2053
PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.... Read more
Affected Products : easyins- Published: Jul. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2051
The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.... Read more
Affected Products : thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs- Published: Jul. 24, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-2047
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.... Read more
Affected Products : easyweb_filemanager- Published: Jul. 23, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1749
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.... Read more
Affected Products : attack_mitigator- Published: Jul. 22, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2055
Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.... Read more
Affected Products : phpbb- Published: Jul. 19, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0488
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-0473
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-... Read more
Affected Products : opera_browser- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0423
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.... Read more
Affected Products : ssmtp- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0471
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of serv... Read more
Affected Products : weblogic_server- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2004-0431
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.... Read more
Affected Products : quicktime- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0401
Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.... Read more
Affected Products : libtasn1- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0398
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0479
Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.... Read more
Affected Products : ie- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0399
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.... Read more
Affected Products : exim- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0402
Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2004-0404
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.... Read more
Affected Products : logcheck- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0482
Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0400
Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.... Read more
Affected Products : exim- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0469
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code du... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2004-0486
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runs... Read more
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025