Latest CVE Feed
-
10.0
HIGHCVE-2004-1769
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.... Read more
- Published: Mar. 04, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0008
Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0096
Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.... Read more
Affected Products : mod_python- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0143
Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.... Read more
Affected Products : 6310i- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0092
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0085
Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0047
Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.... Read more
Affected Products : trr19- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0114
The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, whic... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0086
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0103
crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.... Read more
Affected Products : crawl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0088
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0084
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a differ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0039
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0009
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.... Read more
Affected Products : apache-ssl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0080
The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.... Read more
Affected Products : util-linux- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0127
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0089
Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0099
mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended ac... Read more
Affected Products : freebsd- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0131
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which ... Read more
Affected Products : radius- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025