| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2207 | 0.00 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||
| CVE-2004-2208 | 0.00 | — | 0.00 | Dec 31, 2004 | CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors. | |||
| CVE-2004-2209 | 0.00 | — | 0.00 | Dec 31, 2004 | SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |||
| CVE-2004-2210 | 0.00 | — | 0.00 | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the… | |||
| CVE-2004-2211 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to… | |||
| CVE-2004-2212 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter. | |||
| CVE-2004-2213 | 0.00 | — | 0.00 | Dec 31, 2004 | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request. | |||
| CVE-2004-2214 | Cri | 0.64 | 9.8 | 0.01 | Dec 31, 2004 | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters. | ||
| CVE-2004-2215 | 0.00 | — | 0.00 | Dec 31, 2004 | RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges. | |||
| CVE-2004-2216 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate. | |||
| CVE-2004-2217 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors. | |||
| CVE-2004-2218 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter. | |||
| CVE-2004-2219 | 0.01 | — | 0.15 | Dec 31, 2004 | Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake. | |||
| CVE-2004-2220 | 0.00 | — | 0.01 | Dec 31, 2004 | F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection. | |||
| CVE-2004-2221 | 0.10 | — | 0.81 | Dec 31, 2004 | Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request. | |||
| CVE-2004-2222 | 0.00 | — | 0.01 | Dec 31, 2004 | Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter. | |||
| CVE-2004-2223 | 0.00 | — | 0.01 | Dec 31, 2004 | FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image. | |||
| CVE-2004-2224 | 0.00 | — | 0.01 | Dec 31, 2004 | Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1. | |||
| CVE-2004-2225 | 0.00 | — | 0.01 | Dec 31, 2004 | Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button. | |||
| CVE-2004-2226 | 0.00 | — | 0.00 | Dec 31, 2004 | Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server. | |||
| CVE-2004-2227 | 0.00 | — | 0.01 | Dec 31, 2004 | Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions. | |||
| CVE-2004-2228 | 0.00 | — | 0.00 | Dec 31, 2004 | Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges. | |||
| CVE-2004-2229 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges. | |||
| CVE-2004-2230 | 0.00 | — | 0.00 | Dec 31, 2004 | Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket. | |||
| CVE-2004-2231 | 0.00 | — | 0.00 | Dec 31, 2004 | Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files. | |||
| CVE-2004-2232 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements. | |||
| CVE-2004-2233 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. | |||
| CVE-2004-2234 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators. | |||
| CVE-2004-2235 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. | |||
| CVE-2004-2236 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting. | |||
| CVE-2004-2237 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts." | |||
| CVE-2004-2238 | 0.00 | — | 0.01 | Dec 31, 2004 | Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability | |||
| CVE-2004-2239 | 0.00 | — | 0.01 | Dec 31, 2004 | Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code. | |||
| CVE-2004-2240 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php. | |||
| CVE-2004-2241 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch. | |||
| CVE-2004-2242 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter. | |||
| CVE-2004-2243 | 0.00 | — | 0.01 | Dec 31, 2004 | Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous. | |||
| CVE-2004-2244 | 0.00 | — | 0.01 | Dec 31, 2004 | The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP… | |||
| CVE-2004-2245 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php. | |||
| CVE-2004-2246 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php. | |||
| CVE-2004-2247 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors. | |||
| CVE-2004-2248 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions." | |||
| CVE-2004-2249 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. | |||
| CVE-2004-2250 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. | |||
| CVE-2004-2251 | 0.00 | — | 0.01 | Dec 31, 2004 | The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks. | |||
| CVE-2004-2252 | 0.00 | — | 0.02 | Dec 31, 2004 | The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks. | |||
| CVE-2004-2253 | 0.03 | — | 0.04 | Dec 31, 2004 | Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command. | |||
| CVE-2004-2254 | 0.04 | — | 0.11 | Dec 31, 2004 | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. | |||
| CVE-2004-2255 | 0.00 | — | 0.05 | Dec 31, 2004 | Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename. | |||
| CVE-2004-2256 | 0.00 | — | 0.05 | Dec 31, 2004 | Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable. |
- CVE-2004-2207Dec 31, 2004risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVE-2004-2208Dec 31, 2004risk 0.00cvss —epss 0.00
CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors.
- CVE-2004-2209Dec 31, 2004risk 0.00cvss —epss 0.00
SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
- CVE-2004-2210Dec 31, 2004risk 0.00cvss —epss 0.00
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the…
- CVE-2004-2211Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to…
- CVE-2004-2212Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter.
- CVE-2004-2213Dec 31, 2004risk 0.00cvss —epss 0.00
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
- risk 0.64cvss 9.8epss 0.01
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
- CVE-2004-2215Dec 31, 2004risk 0.00cvss —epss 0.00
RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.
- CVE-2004-2216Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate.
- CVE-2004-2217Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.
- CVE-2004-2218Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.
- CVE-2004-2219Dec 31, 2004risk 0.01cvss —epss 0.15
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.
- CVE-2004-2220Dec 31, 2004risk 0.00cvss —epss 0.01
F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.
- CVE-2004-2221Dec 31, 2004risk 0.10cvss —epss 0.81
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.
- CVE-2004-2222Dec 31, 2004risk 0.00cvss —epss 0.01
Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter.
- CVE-2004-2223Dec 31, 2004risk 0.00cvss —epss 0.01
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.
- CVE-2004-2224Dec 31, 2004risk 0.00cvss —epss 0.01
Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1.
- CVE-2004-2225Dec 31, 2004risk 0.00cvss —epss 0.01
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
- CVE-2004-2226Dec 31, 2004risk 0.00cvss —epss 0.00
Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server.
- CVE-2004-2227Dec 31, 2004risk 0.00cvss —epss 0.01
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
- CVE-2004-2228Dec 31, 2004risk 0.00cvss —epss 0.00
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
- CVE-2004-2229Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.
- CVE-2004-2230Dec 31, 2004risk 0.00cvss —epss 0.00
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
- CVE-2004-2231Dec 31, 2004risk 0.00cvss —epss 0.00
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
- CVE-2004-2232Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
- CVE-2004-2233Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
- CVE-2004-2234Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.
- CVE-2004-2235Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
- CVE-2004-2236Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.
- CVE-2004-2237Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."
- CVE-2004-2238Dec 31, 2004risk 0.00cvss —epss 0.01
Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability
- CVE-2004-2239Dec 31, 2004risk 0.00cvss —epss 0.01
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
- CVE-2004-2240Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.
- CVE-2004-2241Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.
- CVE-2004-2242Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.
- CVE-2004-2243Dec 31, 2004risk 0.00cvss —epss 0.01
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.
- CVE-2004-2244Dec 31, 2004risk 0.00cvss —epss 0.01
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP…
- CVE-2004-2245Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.
- CVE-2004-2246Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.
- CVE-2004-2247Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.
- CVE-2004-2248Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."
- CVE-2004-2249Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.
- CVE-2004-2250Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.
- CVE-2004-2251Dec 31, 2004risk 0.00cvss —epss 0.01
The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.
- CVE-2004-2252Dec 31, 2004risk 0.00cvss —epss 0.02
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.
- CVE-2004-2253Dec 31, 2004risk 0.03cvss —epss 0.04
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.
- CVE-2004-2254Dec 31, 2004risk 0.04cvss —epss 0.11
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.
- CVE-2004-2255Dec 31, 2004risk 0.00cvss —epss 0.05
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.
- CVE-2004-2256Dec 31, 2004risk 0.00cvss —epss 0.05
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.