VYPR

CVEs

340,759 total · page 6619 of 6,816

  • CVE-2004-2207Dec 31, 2004
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2004-2208Dec 31, 2004
    risk 0.00cvss epss 0.00

    CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors.

  • CVE-2004-2209Dec 31, 2004
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2004-2210Dec 31, 2004
    risk 0.00cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the…

  • CVE-2004-2211Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to…

  • CVE-2004-2212Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter.

  • CVE-2004-2213Dec 31, 2004
    risk 0.00cvss epss 0.00

    Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.

  • CVE-2004-2214CriDec 31, 2004
    risk 0.64cvss 9.8epss 0.01

    Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.

  • CVE-2004-2215Dec 31, 2004
    risk 0.00cvss epss 0.00

    RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.

  • CVE-2004-2216Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate.

  • CVE-2004-2217Dec 31, 2004
    risk 0.00cvss epss 0.01

    Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.

  • CVE-2004-2218Dec 31, 2004
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.

  • CVE-2004-2219Dec 31, 2004
    risk 0.01cvss epss 0.15

    Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.

  • CVE-2004-2220Dec 31, 2004
    risk 0.00cvss epss 0.01

    F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.

  • CVE-2004-2221Dec 31, 2004
    risk 0.10cvss epss 0.81

    Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.

  • CVE-2004-2222Dec 31, 2004
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter.

  • CVE-2004-2223Dec 31, 2004
    risk 0.00cvss epss 0.01

    FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.

  • CVE-2004-2224Dec 31, 2004
    risk 0.00cvss epss 0.01

    Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1.

  • CVE-2004-2225Dec 31, 2004
    risk 0.00cvss epss 0.01

    Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.

  • CVE-2004-2226Dec 31, 2004
    risk 0.00cvss epss 0.00

    Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server.

  • CVE-2004-2227Dec 31, 2004
    risk 0.00cvss epss 0.01

    Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.

  • CVE-2004-2228Dec 31, 2004
    risk 0.00cvss epss 0.00

    Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.

  • CVE-2004-2229Dec 31, 2004
    risk 0.00cvss epss 0.01

    Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.

  • CVE-2004-2230Dec 31, 2004
    risk 0.00cvss epss 0.00

    Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.

  • CVE-2004-2231Dec 31, 2004
    risk 0.00cvss epss 0.00

    Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.

  • CVE-2004-2232Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

  • CVE-2004-2233Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

  • CVE-2004-2234Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.

  • CVE-2004-2235Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.

  • CVE-2004-2236Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

  • CVE-2004-2237Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."

  • CVE-2004-2238Dec 31, 2004
    risk 0.00cvss epss 0.01

    Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability

  • CVE-2004-2239Dec 31, 2004
    risk 0.00cvss epss 0.01

    Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.

  • CVE-2004-2240Dec 31, 2004
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.

  • CVE-2004-2241Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.

  • CVE-2004-2242Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.

  • CVE-2004-2243Dec 31, 2004
    risk 0.00cvss epss 0.01

    Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.

  • CVE-2004-2244Dec 31, 2004
    risk 0.00cvss epss 0.01

    The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP…

  • CVE-2004-2245Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.

  • CVE-2004-2246Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.

  • CVE-2004-2247Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.

  • CVE-2004-2248Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."

  • CVE-2004-2249Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.

  • CVE-2004-2250Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.

  • CVE-2004-2251Dec 31, 2004
    risk 0.00cvss epss 0.01

    The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.

  • CVE-2004-2252Dec 31, 2004
    risk 0.00cvss epss 0.02

    The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.

  • CVE-2004-2253Dec 31, 2004
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.

  • CVE-2004-2254Dec 31, 2004
    risk 0.04cvss epss 0.11

    SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.

  • CVE-2004-2255Dec 31, 2004
    risk 0.00cvss epss 0.05

    Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

  • CVE-2004-2256Dec 31, 2004
    risk 0.00cvss epss 0.05

    Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.