Latest CVE Feed
-
5.0
MEDIUMCVE-2004-1941
Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.... Read more
Affected Products : netfile_ftp_web_server- Published: Apr. 19, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1943
PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.... Read more
- Published: Apr. 19, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1035
The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0594
Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a ... Read more
Affected Products : mozilla- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0111
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0905
Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1036
Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.... Read more
Affected Products : internet_transaction_server- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0202
The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : metrics- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0514
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. t... Read more
Affected Products : safari- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1039
Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server.... Read more
Affected Products : mysap_business_suite- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0121
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execut... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0257
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.... Read more
Affected Products : aix- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0593
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vuln... Read more
Affected Products : opera_browser- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0152
Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachm... Read more
Affected Products : emil- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0108
The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0148
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1934
PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.... Read more
Affected Products : gemitel- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0592
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outsid... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1579
SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.... Read more
Affected Products : sapgui- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1577
SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.... Read more
Affected Products : sap_r_3- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025