| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2257 | Med | 0.35 | 5.3 | 0.01 | Dec 31, 2004 | phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request. | ||
| CVE-2004-2258 | 0.00 | — | 0.00 | Dec 31, 2004 | Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab. | |||
| CVE-2004-2259 | 0.00 | — | 0.02 | Dec 31, 2004 | vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant. | |||
| CVE-2004-2260 | 0.00 | — | 0.01 | Dec 31, 2004 | Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute. | |||
| CVE-2004-2261 | 0.00 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions. | |||
| CVE-2004-2262 | 0.04 | — | 0.18 | Dec 31, 2004 | ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php. | |||
| CVE-2004-2263 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie. | |||
| CVE-2004-2264 | 0.00 | — | 0.01 | Dec 31, 2004 | Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid,… | |||
| CVE-2004-2265 | 0.00 | — | 0.00 | Dec 31, 2004 | UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact. | |||
| CVE-2004-2266 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter. | |||
| CVE-2004-2267 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via the album name. | |||
| CVE-2004-2268 | 0.00 | — | 0.01 | Dec 31, 2004 | PimenGest2 before 1.1.1 allows remote attackers to obtain the database password via debug information in rowLatex.inc.php. | |||
| CVE-2004-2269 | 0.00 | — | 0.00 | Dec 31, 2004 | Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability. | |||
| CVE-2004-2270 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code. | |||
| CVE-2004-2271 | 0.10 | — | 0.82 | Dec 31, 2004 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||
| CVE-2004-2272 | 0.00 | — | 0.01 | Dec 31, 2004 | Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command. | |||
| CVE-2004-2273 | 0.00 | — | 0.01 | Dec 31, 2004 | efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error. | |||
| CVE-2004-2274 | — | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI. | ||
| CVE-2004-2275 | 0.04 | — | 0.07 | Dec 31, 2004 | i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. | |||
| CVE-2004-2276 | 0.00 | — | 0.00 | Dec 31, 2004 | F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection. | |||
| CVE-2004-2277 | 0.04 | — | 0.07 | Dec 31, 2004 | Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response. | |||
| CVE-2004-2278 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors. | |||
| CVE-2004-2279 | 0.00 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php. | |||
| CVE-2004-2280 | 0.03 | — | 0.04 | Dec 31, 2004 | Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN. | |||
| CVE-2004-2281 | 0.00 | — | 0.00 | Dec 31, 2004 | Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3. | |||
| CVE-2004-2282 | 0.00 | — | 0.00 | Dec 31, 2004 | DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request. | |||
| CVE-2004-2283 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache. | |||
| CVE-2004-2284 | 0.00 | — | 0.04 | Dec 31, 2004 | The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument. | |||
| CVE-2004-2286 | 0.05 | — | 0.23 | Dec 31, 2004 | Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow. | |||
| CVE-2004-2287 | 0.03 | — | 0.05 | Dec 31, 2004 | Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter. | |||
| CVE-2004-2288 | 0.03 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter. | |||
| CVE-2004-2289 | 0.04 | — | 0.12 | Dec 31, 2004 | Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file. | |||
| CVE-2004-2290 | 0.00 | — | 0.01 | Dec 31, 2004 | Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder. | |||
| CVE-2004-2291 | 0.04 | — | 0.16 | Dec 31, 2004 | Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script. | |||
| CVE-2004-2292 | 0.00 | — | 0.02 | Dec 31, 2004 | Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server. | |||
| CVE-2004-2293 | 0.03 | — | 0.00 | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated… | |||
| CVE-2004-2294 | 0.03 | — | 0.00 | Dec 31, 2004 | Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is… | |||
| CVE-2004-2295 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |||
| CVE-2004-2296 | 0.00 | — | 0.00 | Dec 31, 2004 | The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitive information via an invalid date parameter, which generates an error message. | |||
| CVE-2004-2297 | 0.03 | — | 0.00 | Dec 31, 2004 | The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter. | |||
| CVE-2004-2298 | 0.00 | — | 0.00 | Dec 31, 2004 | Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP… | |||
| CVE-2004-2299 | 0.04 | — | 0.07 | Dec 31, 2004 | Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header. | |||
| CVE-2004-2300 | 0.00 | — | 0.00 | Dec 31, 2004 | Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -p command line argument. NOTE: it is not clear whether there are any standard configurations in which snmpd is installed setuid or… | |||
| CVE-2004-2301 | 0.00 | — | 0.01 | Dec 31, 2004 | Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow. | |||
| CVE-2004-2302 | 0.00 | — | 0.00 | Dec 31, 2004 | Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to read kernel memory and cause a denial of service (crash) via large offsets in sysfs files. | |||
| CVE-2004-2303 | 0.03 | — | 0.01 | Dec 31, 2004 | MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files. | |||
| CVE-2004-2304 | 0.00 | — | 0.03 | Dec 31, 2004 | Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow. | |||
| CVE-2004-2305 | 0.00 | — | 0.00 | Dec 31, 2004 | Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files. | |||
| CVE-2004-2306 | 0.00 | — | 0.00 | Dec 31, 2004 | Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection. | |||
| CVE-2004-2307 | 0.01 | — | 0.10 | Dec 31, 2004 | Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A. |
- risk 0.35cvss 5.3epss 0.01
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
- CVE-2004-2258Dec 31, 2004risk 0.00cvss —epss 0.00
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
- CVE-2004-2259Dec 31, 2004risk 0.00cvss —epss 0.02
vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant.
- CVE-2004-2260Dec 31, 2004risk 0.00cvss —epss 0.01
Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.
- CVE-2004-2261Dec 31, 2004risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.
- CVE-2004-2262Dec 31, 2004risk 0.04cvss —epss 0.18
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.
- CVE-2004-2263Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.
- CVE-2004-2264Dec 31, 2004risk 0.00cvss —epss 0.01
Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid,…
- CVE-2004-2265Dec 31, 2004risk 0.00cvss —epss 0.00
UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.
- CVE-2004-2266Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter.
- CVE-2004-2267Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via the album name.
- CVE-2004-2268Dec 31, 2004risk 0.00cvss —epss 0.01
PimenGest2 before 1.1.1 allows remote attackers to obtain the database password via debug information in rowLatex.inc.php.
- CVE-2004-2269Dec 31, 2004risk 0.00cvss —epss 0.00
Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability.
- CVE-2004-2270Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.
- CVE-2004-2271Dec 31, 2004risk 0.10cvss —epss 0.82
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-2272Dec 31, 2004risk 0.00cvss —epss 0.01
Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.
- CVE-2004-2273Dec 31, 2004risk 0.00cvss —epss 0.01
efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.
- CVE-2004-2274Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
- CVE-2004-2275Dec 31, 2004risk 0.04cvss —epss 0.07
i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.
- CVE-2004-2276Dec 31, 2004risk 0.00cvss —epss 0.00
F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection.
- CVE-2004-2277Dec 31, 2004risk 0.04cvss —epss 0.07
Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response.
- CVE-2004-2278Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors.
- CVE-2004-2279Dec 31, 2004risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
- CVE-2004-2280Dec 31, 2004risk 0.03cvss —epss 0.04
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.
- CVE-2004-2281Dec 31, 2004risk 0.00cvss —epss 0.00
Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.
- CVE-2004-2282Dec 31, 2004risk 0.00cvss —epss 0.00
DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.
- CVE-2004-2283Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.
- CVE-2004-2284Dec 31, 2004risk 0.00cvss —epss 0.04
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
- CVE-2004-2286Dec 31, 2004risk 0.05cvss —epss 0.23
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.
- CVE-2004-2287Dec 31, 2004risk 0.03cvss —epss 0.05
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.
- CVE-2004-2288Dec 31, 2004risk 0.03cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.
- CVE-2004-2289Dec 31, 2004risk 0.04cvss —epss 0.12
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.
- CVE-2004-2290Dec 31, 2004risk 0.00cvss —epss 0.01
Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder.
- CVE-2004-2291Dec 31, 2004risk 0.04cvss —epss 0.16
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.
- CVE-2004-2292Dec 31, 2004risk 0.00cvss —epss 0.02
Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server.
- CVE-2004-2293Dec 31, 2004risk 0.03cvss —epss 0.00
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated…
- CVE-2004-2294Dec 31, 2004risk 0.03cvss —epss 0.00
Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is…
- CVE-2004-2295Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter.
- CVE-2004-2296Dec 31, 2004risk 0.00cvss —epss 0.00
The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitive information via an invalid date parameter, which generates an error message.
- CVE-2004-2297Dec 31, 2004risk 0.03cvss —epss 0.00
The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter.
- CVE-2004-2298Dec 31, 2004risk 0.00cvss —epss 0.00
Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP…
- CVE-2004-2299Dec 31, 2004risk 0.04cvss —epss 0.07
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.
- CVE-2004-2300Dec 31, 2004risk 0.00cvss —epss 0.00
Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -p command line argument. NOTE: it is not clear whether there are any standard configurations in which snmpd is installed setuid or…
- CVE-2004-2301Dec 31, 2004risk 0.00cvss —epss 0.01
Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow.
- CVE-2004-2302Dec 31, 2004risk 0.00cvss —epss 0.00
Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to read kernel memory and cause a denial of service (crash) via large offsets in sysfs files.
- CVE-2004-2303Dec 31, 2004risk 0.03cvss —epss 0.01
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.
- CVE-2004-2304Dec 31, 2004risk 0.00cvss —epss 0.03
Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.
- CVE-2004-2305Dec 31, 2004risk 0.00cvss —epss 0.00
Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files.
- CVE-2004-2306Dec 31, 2004risk 0.00cvss —epss 0.00
Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.
- CVE-2004-2307Dec 31, 2004risk 0.01cvss —epss 0.10
Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.