| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2411 | 0.03 | — | 0.01 | Dec 31, 2004 | The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use tags, as demonstrated via javascript in IMG tags to (1)… | |||
| CVE-2004-2412 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shopreviewlist.asp and (2) shopreviewadd.asp. | |||
| CVE-2004-2413 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp. | |||
| CVE-2004-2414 | 0.00 | — | 0.00 | Dec 31, 2004 | Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords. | |||
| CVE-2004-2415 | 0.00 | — | 0.01 | Dec 31, 2004 | Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks. | |||
| CVE-2004-2416 | 0.09 | — | 0.75 | Dec 31, 2004 | Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||
| CVE-2004-2417 | 0.00 | — | 0.02 | Dec 31, 2004 | Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message. | |||
| CVE-2004-2418 | 0.03 | — | 0.00 | Dec 31, 2004 | Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT. | |||
| CVE-2004-2419 | 0.00 | — | 0.00 | Dec 31, 2004 | Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system. | |||
| CVE-2004-2420 | 0.00 | — | 0.01 | Dec 31, 2004 | Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7 allows remote attackers to cause a denial of service (daemon halt) via a port scan involving reset packets. | |||
| CVE-2004-2421 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted mode, allows attackers to bypass authentication and gain administrator rights. | |||
| CVE-2004-2422 | 0.00 | — | 0.00 | Dec 31, 2004 | Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Manager or (2) a long To field to the Web Messaging component. | |||
| CVE-2004-2423 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content." | |||
| CVE-2004-2424 | 0.00 | — | 0.01 | Dec 31, 2004 | BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends. | |||
| CVE-2004-2425 | 0.05 | — | 0.26 | Dec 31, 2004 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi. | |||
| CVE-2004-2426 | 0.00 | — | 0.01 | Dec 31, 2004 | Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities,… | |||
| CVE-2004-2427 | 0.00 | — | 0.05 | Dec 31, 2004 | Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system… | |||
| CVE-2004-2428 | 0.00 | — | 0.00 | Dec 31, 2004 | Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password. | |||
| CVE-2004-2429 | 0.00 | — | 0.05 | Dec 31, 2004 | Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in… | |||
| CVE-2004-2430 | 0.00 | — | 0.00 | Dec 31, 2004 | Trend OfficeScan Corporate Edition 5.58 and possibly earler does not drop privileges when opening a help window from a virus detection pop-up window, which allows local users to gain SYSTEM privileges. | |||
| CVE-2004-2431 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in The Ignition Project ignitionServer 0.1.2 through 0.3.1, with the linking service enabled, allows remote attackers to bypass authentication. | |||
| CVE-2004-2432 | 0.00 | — | 0.01 | Dec 31, 2004 | WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow. | |||
| CVE-2004-2433 | 0.01 | — | 0.07 | Dec 31, 2004 | Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath… | |||
| CVE-2004-2434 | 0.04 | — | 0.09 | Dec 31, 2004 | Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an… | |||
| CVE-2004-2435 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts. | |||
| CVE-2004-2436 | 0.00 | — | 0.00 | Dec 31, 2004 | Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | |||
| CVE-2004-2437 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php. | |||
| CVE-2004-2438 | 0.00 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field. | |||
| CVE-2004-2439 | 0.00 | — | 0.01 | Dec 31, 2004 | The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware. | |||
| CVE-2004-2440 | 0.00 | — | 0.00 | Dec 31, 2004 | Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users. | |||
| CVE-2004-2441 | 0.00 | — | 0.00 | Dec 31, 2004 | Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue." | |||
| CVE-2004-2442 | 0.05 | — | 0.19 | Dec 31, 2004 | Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers… | |||
| CVE-2004-2443 | 0.03 | — | 0.06 | Dec 31, 2004 | Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php. | |||
| CVE-2004-2444 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |||
| CVE-2004-2445 | 0.04 | — | 0.10 | Dec 31, 2004 | Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter. | |||
| CVE-2004-2446 | 0.00 | — | 0.01 | Dec 31, 2004 | Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors. | |||
| CVE-2004-2447 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6)… | |||
| CVE-2004-2448 | 0.00 | — | 0.00 | Dec 31, 2004 | S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name. | |||
| CVE-2004-2449 | 0.05 | — | 0.20 | Dec 31, 2004 | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram. | |||
| CVE-2004-2450 | 0.00 | — | 0.01 | Dec 31, 2004 | The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information. | |||
| CVE-2004-2451 | 0.03 | — | 0.04 | Dec 31, 2004 | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. | |||
| CVE-2004-2452 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |||
| CVE-2004-2453 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors. | |||
| CVE-2004-2454 | 0.00 | — | 0.00 | Dec 31, 2004 | aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hotlog.htm and (2) config.xml. | |||
| CVE-2004-2455 | 0.00 | — | 0.02 | Dec 31, 2004 | Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file. | |||
| CVE-2004-2456 | 0.03 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action. | |||
| CVE-2004-2457 | — | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic. | ||
| CVE-2004-2458 | 0.00 | — | 0.00 | Dec 31, 2004 | Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories. | |||
| CVE-2004-2459 | 0.00 | — | 0.00 | Dec 31, 2004 | Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table. | |||
| CVE-2004-2460 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list. |
- CVE-2004-2411Dec 31, 2004risk 0.03cvss —epss 0.01
The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use tags, as demonstrated via javascript in IMG tags to (1)…
- CVE-2004-2412Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shopreviewlist.asp and (2) shopreviewadd.asp.
- CVE-2004-2413Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.
- CVE-2004-2414Dec 31, 2004risk 0.00cvss —epss 0.00
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
- CVE-2004-2415Dec 31, 2004risk 0.00cvss —epss 0.01
Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks.
- CVE-2004-2416Dec 31, 2004risk 0.09cvss —epss 0.75
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-2417Dec 31, 2004risk 0.00cvss —epss 0.02
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
- CVE-2004-2418Dec 31, 2004risk 0.03cvss —epss 0.00
Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT.
- CVE-2004-2419Dec 31, 2004risk 0.00cvss —epss 0.00
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system.
- CVE-2004-2420Dec 31, 2004risk 0.00cvss —epss 0.01
Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7 allows remote attackers to cause a denial of service (daemon halt) via a port scan involving reset packets.
- CVE-2004-2421Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted mode, allows attackers to bypass authentication and gain administrator rights.
- CVE-2004-2422Dec 31, 2004risk 0.00cvss —epss 0.00
Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Manager or (2) a long To field to the Web Messaging component.
- CVE-2004-2423Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content."
- CVE-2004-2424Dec 31, 2004risk 0.00cvss —epss 0.01
BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.
- CVE-2004-2425Dec 31, 2004risk 0.05cvss —epss 0.26
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
- CVE-2004-2426Dec 31, 2004risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities,…
- CVE-2004-2427Dec 31, 2004risk 0.00cvss —epss 0.05
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system…
- CVE-2004-2428Dec 31, 2004risk 0.00cvss —epss 0.00
Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password.
- CVE-2004-2429Dec 31, 2004risk 0.00cvss —epss 0.05
Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in…
- CVE-2004-2430Dec 31, 2004risk 0.00cvss —epss 0.00
Trend OfficeScan Corporate Edition 5.58 and possibly earler does not drop privileges when opening a help window from a virus detection pop-up window, which allows local users to gain SYSTEM privileges.
- CVE-2004-2431Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in The Ignition Project ignitionServer 0.1.2 through 0.3.1, with the linking service enabled, allows remote attackers to bypass authentication.
- CVE-2004-2432Dec 31, 2004risk 0.00cvss —epss 0.01
WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.
- CVE-2004-2433Dec 31, 2004risk 0.01cvss —epss 0.07
Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath…
- CVE-2004-2434Dec 31, 2004risk 0.04cvss —epss 0.09
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an…
- CVE-2004-2435Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.
- CVE-2004-2436Dec 31, 2004risk 0.00cvss —epss 0.00
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.
- CVE-2004-2437Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.
- CVE-2004-2438Dec 31, 2004risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.
- CVE-2004-2439Dec 31, 2004risk 0.00cvss —epss 0.01
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
- CVE-2004-2440Dec 31, 2004risk 0.00cvss —epss 0.00
Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users.
- CVE-2004-2441Dec 31, 2004risk 0.00cvss —epss 0.00
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."
- CVE-2004-2442Dec 31, 2004risk 0.05cvss —epss 0.19
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers…
- CVE-2004-2443Dec 31, 2004risk 0.03cvss —epss 0.06
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
- CVE-2004-2444Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
- CVE-2004-2445Dec 31, 2004risk 0.04cvss —epss 0.10
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.
- CVE-2004-2446Dec 31, 2004risk 0.00cvss —epss 0.01
Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors.
- CVE-2004-2447Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6)…
- CVE-2004-2448Dec 31, 2004risk 0.00cvss —epss 0.00
S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name.
- CVE-2004-2449Dec 31, 2004risk 0.05cvss —epss 0.20
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.
- CVE-2004-2450Dec 31, 2004risk 0.00cvss —epss 0.01
The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information.
- CVE-2004-2451Dec 31, 2004risk 0.03cvss —epss 0.04
Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug.
- CVE-2004-2452Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.
- CVE-2004-2453Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors.
- CVE-2004-2454Dec 31, 2004risk 0.00cvss —epss 0.00
aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hotlog.htm and (2) config.xml.
- CVE-2004-2455Dec 31, 2004risk 0.00cvss —epss 0.02
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
- CVE-2004-2456Dec 31, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.
- CVE-2004-2457Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.
- CVE-2004-2458Dec 31, 2004risk 0.00cvss —epss 0.00
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
- CVE-2004-2459Dec 31, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.
- CVE-2004-2460Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.