VYPR

CVEs

340,756 total · page 6624 of 6,816

  • CVE-2004-2462Dec 31, 2004
    risk 0.00cvss epss 0.00

    cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file.

  • CVE-2004-2463Dec 31, 2004
    risk 0.01cvss epss 0.09

    Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.

  • CVE-2004-2464Dec 31, 2004
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

  • CVE-2004-2465Dec 31, 2004
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

  • CVE-2004-2466Dec 31, 2004
    risk 0.07cvss epss 0.78

    chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

  • CVE-2004-2467Dec 31, 2004
    risk 0.00cvss epss 0.02

    chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).

  • CVE-2004-2468Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2004-2469Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

  • CVE-2004-2470Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.

  • CVE-2004-2471Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2004-2472Dec 31, 2004
    risk 0.00cvss epss 0.01

    Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.

  • CVE-2004-2473Dec 31, 2004
    risk 0.00cvss epss 0.00

    wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2004-2474Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

  • CVE-2004-2475Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege…

  • CVE-2004-2476Dec 31, 2004
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.

  • CVE-2004-2477Dec 31, 2004
    risk 0.00cvss epss 0.00

    DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.

  • CVE-2004-2478Dec 31, 2004
    risk 0.00cvss epss 0.04

    Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot)…

  • CVE-2004-2479Dec 31, 2004
    risk 0.00cvss epss 0.01

    Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.

  • CVE-2004-2480Dec 31, 2004
    risk 0.03cvss epss 0.02

    Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

  • CVE-2004-2481Dec 31, 2004
    risk 0.00cvss epss 0.00

    MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.

  • CVE-2004-2482Dec 31, 2004
    risk 0.02cvss epss 0.21

    Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in…

  • CVE-2004-2483Dec 31, 2004
    risk 0.00cvss epss 0.01

    Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).

  • CVE-2004-2484Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.

  • CVE-2004-2485Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

  • CVE-2004-2486Dec 31, 2004
    risk 0.00cvss epss 0.02

    The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

  • CVE-2004-2487Dec 31, 2004
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO…

  • CVE-2004-2488Dec 31, 2004
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.

  • CVE-2004-2489Dec 31, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.

  • CVE-2004-2490Dec 31, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.

  • CVE-2004-2491Dec 31, 2004
    risk 0.04cvss epss 0.10

    A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing…

  • CVE-2004-2492Dec 31, 2004
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.

  • CVE-2004-2493Dec 31, 2004
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

  • CVE-2004-2494Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

  • CVE-2004-2495Dec 31, 2004
    risk 0.00cvss epss 0.02

    The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.

  • CVE-2004-2496Dec 31, 2004
    risk 0.04cvss epss 0.08

    The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.

  • CVE-2004-2497Dec 31, 2004
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via…

  • CVE-2004-2498Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown…

  • CVE-2004-2499Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."

  • CVE-2004-2500Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

  • CVE-2004-2501Dec 31, 2004
    risk 0.08cvss epss 0.61

    Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.

  • CVE-2004-2502Dec 31, 2004
    risk 0.03cvss epss 0.00

    im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.

  • CVE-2004-2503Dec 31, 2004
    risk 0.00cvss epss 0.01

    INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.

  • CVE-2004-2504Dec 31, 2004
    risk 0.00cvss epss 0.00

    The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.

  • CVE-2004-2505Dec 31, 2004
    risk 0.06cvss epss 0.31

    Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.

  • CVE-2004-2506Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file.

  • CVE-2004-2507Dec 31, 2004
    risk 0.04cvss epss 0.07

    Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

  • CVE-2004-2508Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.

  • CVE-2004-2509Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.

  • CVE-2004-2510Dec 31, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.

  • CVE-2004-2511Dec 31, 2004
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid…