| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-1481 | 0.01 | — | 0.07 | Dec 31, 2004 | Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which… | |||
| CVE-2004-1482 | 0.00 | — | 0.01 | Dec 31, 2004 | The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts. | |||
| CVE-2004-1483 | 0.00 | — | 0.03 | Dec 31, 2004 | Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact. | |||
| CVE-2004-1484 | 0.03 | — | 0.02 | Dec 31, 2004 | Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message. | |||
| CVE-2004-1485 | 0.00 | — | 0.02 | Dec 31, 2004 | Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function. | |||
| CVE-2004-1486 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain… | |||
| CVE-2004-1489 | 0.00 | — | 0.00 | Dec 31, 2004 | Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory. | |||
| CVE-2004-1490 | 0.00 | — | 0.01 | Dec 31, 2004 | Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers. | |||
| CVE-2004-1491 | 0.05 | — | 0.26 | Dec 31, 2004 | Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry. | |||
| CVE-2004-1492 | 0.00 | — | 0.01 | Dec 31, 2004 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail. | |||
| CVE-2004-1493 | 0.03 | — | 0.05 | Dec 31, 2004 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow. | |||
| CVE-2004-1494 | 0.00 | — | 0.02 | Dec 31, 2004 | Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string. | |||
| CVE-2004-1495 | 0.00 | — | 0.01 | Dec 31, 2004 | The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive. | |||
| CVE-2004-1496 | 0.00 | — | 0.00 | Dec 31, 2004 | Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded… | |||
| CVE-2004-1497 | 0.00 | — | 0.00 | Dec 31, 2004 | Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |||
| CVE-2004-1498 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | |||
| CVE-2004-1499 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field. | |||
| CVE-2004-1500 | 0.03 | — | 0.01 | Dec 31, 2004 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |||
| CVE-2004-1501 | 0.00 | — | 0.01 | Dec 31, 2004 | The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data. | |||
| CVE-2004-1502 | 0.00 | — | 0.01 | Dec 31, 2004 | The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop. | |||
| CVE-2004-1503 | 0.00 | — | 0.01 | Dec 31, 2004 | Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to… | |||
| CVE-2004-1504 | 0.00 | — | 0.00 | Dec 31, 2004 | The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php. | |||
| CVE-2004-1505 | 0.00 | — | 0.01 | Dec 31, 2004 | Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter. | |||
| CVE-2004-1506 | 0.00 | — | 0.00 | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags. | |||
| CVE-2004-1507 | 0.00 | — | 0.00 | Dec 31, 2004 | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server. | |||
| CVE-2004-1508 | 0.00 | — | 0.01 | Dec 31, 2004 | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. | |||
| CVE-2004-1509 | — | 0.00 | — | 0.00 | Dec 31, 2004 | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message. | ||
| CVE-2004-1510 | 0.00 | — | 0.01 | Dec 31, 2004 | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | |||
| CVE-2004-1511 | 0.00 | — | 0.01 | Dec 31, 2004 | Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window. | |||
| CVE-2004-1512 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page. | |||
| CVE-2004-1513 | 0.00 | — | 0.01 | Dec 31, 2004 | 04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries. | |||
| CVE-2004-1514 | 0.00 | — | 0.01 | Dec 31, 2004 | 04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2. | |||
| CVE-2004-1515 | 0.03 | — | 0.00 | Dec 31, 2004 | SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php. | |||
| CVE-2004-1516 | 0.00 | — | 0.01 | Dec 31, 2004 | CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module. | |||
| CVE-2004-1517 | 0.00 | — | 0.00 | Dec 31, 2004 | Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions. | |||
| CVE-2004-1518 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter. | |||
| CVE-2004-1519 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation. | |||
| CVE-2004-1520 | 0.10 | — | 0.89 | Dec 31, 2004 | Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. | |||
| CVE-2004-1521 | 0.03 | — | 0.03 | Dec 31, 2004 | Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers. | |||
| CVE-2004-1522 | — | 0.00 | — | 0.01 | Dec 31, 2004 | Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings. | ||
| CVE-2004-1523 | 0.00 | — | 0.01 | Dec 31, 2004 | Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message. | |||
| CVE-2004-1524 | 0.00 | — | 0.01 | Dec 31, 2004 | Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200. | |||
| CVE-2004-1525 | 0.00 | — | 0.01 | Dec 31, 2004 | Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command. | |||
| CVE-2004-1526 | 0.00 | — | 0.00 | Dec 31, 2004 | Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator. | |||
| CVE-2004-1527 | 0.00 | — | 0.00 | Dec 31, 2004 | Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows… | |||
| CVE-2004-1528 | 0.00 | — | 0.01 | Dec 31, 2004 | The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message. | |||
| CVE-2004-1529 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments. | |||
| CVE-2004-1530 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters. | |||
| CVE-2004-1531 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | |||
| CVE-2004-1532 | 0.00 | — | 0.01 | Dec 31, 2004 | AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access. |
- CVE-2004-1481Dec 31, 2004risk 0.01cvss —epss 0.07
Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which…
- CVE-2004-1482Dec 31, 2004risk 0.00cvss —epss 0.01
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
- CVE-2004-1483Dec 31, 2004risk 0.00cvss —epss 0.03
Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.
- CVE-2004-1484Dec 31, 2004risk 0.03cvss —epss 0.02
Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
- CVE-2004-1485Dec 31, 2004risk 0.00cvss —epss 0.02
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.
- CVE-2004-1486Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain…
- CVE-2004-1489Dec 31, 2004risk 0.00cvss —epss 0.00
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
- CVE-2004-1490Dec 31, 2004risk 0.00cvss —epss 0.01
Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.
- CVE-2004-1491Dec 31, 2004risk 0.05cvss —epss 0.26
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.
- CVE-2004-1492Dec 31, 2004risk 0.00cvss —epss 0.01
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.
- CVE-2004-1493Dec 31, 2004risk 0.03cvss —epss 0.05
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.
- CVE-2004-1494Dec 31, 2004risk 0.00cvss —epss 0.02
Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.
- CVE-2004-1495Dec 31, 2004risk 0.00cvss —epss 0.01
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.
- CVE-2004-1496Dec 31, 2004risk 0.00cvss —epss 0.00
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded…
- CVE-2004-1497Dec 31, 2004risk 0.00cvss —epss 0.00
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
- CVE-2004-1498Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
- CVE-2004-1499Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
- CVE-2004-1500Dec 31, 2004risk 0.03cvss —epss 0.01
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
- CVE-2004-1501Dec 31, 2004risk 0.00cvss —epss 0.01
The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.
- CVE-2004-1502Dec 31, 2004risk 0.00cvss —epss 0.01
The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.
- CVE-2004-1503Dec 31, 2004risk 0.00cvss —epss 0.01
Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to…
- CVE-2004-1504Dec 31, 2004risk 0.00cvss —epss 0.00
The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.
- CVE-2004-1505Dec 31, 2004risk 0.00cvss —epss 0.01
Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.
- CVE-2004-1506Dec 31, 2004risk 0.00cvss —epss 0.00
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.
- CVE-2004-1507Dec 31, 2004risk 0.00cvss —epss 0.00
CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.
- CVE-2004-1508Dec 31, 2004risk 0.00cvss —epss 0.01
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
- CVE-2004-1509Dec 31, 2004risk 0.00cvss —epss 0.00
validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.
- CVE-2004-1510Dec 31, 2004risk 0.00cvss —epss 0.01
WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.
- CVE-2004-1511Dec 31, 2004risk 0.00cvss —epss 0.01
Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.
- CVE-2004-1512Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.
- CVE-2004-1513Dec 31, 2004risk 0.00cvss —epss 0.01
04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.
- CVE-2004-1514Dec 31, 2004risk 0.00cvss —epss 0.01
04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.
- CVE-2004-1515Dec 31, 2004risk 0.03cvss —epss 0.00
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
- CVE-2004-1516Dec 31, 2004risk 0.00cvss —epss 0.01
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.
- CVE-2004-1517Dec 31, 2004risk 0.00cvss —epss 0.00
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
- CVE-2004-1518Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.
- CVE-2004-1519Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.
- CVE-2004-1520Dec 31, 2004risk 0.10cvss —epss 0.89
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.
- CVE-2004-1521Dec 31, 2004risk 0.03cvss —epss 0.03
Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.
- CVE-2004-1522Dec 31, 2004risk 0.00cvss —epss 0.01
Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.
- CVE-2004-1523Dec 31, 2004risk 0.00cvss —epss 0.01
Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.
- CVE-2004-1524Dec 31, 2004risk 0.00cvss —epss 0.01
Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.
- CVE-2004-1525Dec 31, 2004risk 0.00cvss —epss 0.01
Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.
- CVE-2004-1526Dec 31, 2004risk 0.00cvss —epss 0.00
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.
- CVE-2004-1527Dec 31, 2004risk 0.00cvss —epss 0.00
Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows…
- CVE-2004-1528Dec 31, 2004risk 0.00cvss —epss 0.01
The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.
- CVE-2004-1529Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.
- CVE-2004-1530Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.
- CVE-2004-1531Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.
- CVE-2004-1532Dec 31, 2004risk 0.00cvss —epss 0.01
AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.