VYPR

CVEs

340,756 total · page 6625 of 6,816

  • CVE-2004-2512Dec 31, 2004
    risk 0.04cvss epss 0.10

    CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.

  • CVE-2004-2513Dec 31, 2004
    risk 0.06cvss epss 0.32

    Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.

  • CVE-2004-2514Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.

  • CVE-2004-2515Dec 31, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical…

  • CVE-2004-2516Dec 31, 2004
    risk 0.04cvss epss 0.11

    Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

  • CVE-2004-2517Dec 31, 2004
    risk 0.04cvss epss 0.06

    myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.

  • CVE-2004-2518Dec 31, 2004
    risk 0.04cvss epss 0.13

    Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.

  • CVE-2004-2519Dec 31, 2004
    risk 0.04cvss epss 0.07

    Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal…

  • CVE-2004-2520Dec 31, 2004
    risk 0.03cvss epss 0.06

    POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.

  • CVE-2004-2521Dec 31, 2004
    risk 0.00cvss epss 0.01

    Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).

  • CVE-2004-2522Dec 31, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

  • CVE-2004-2523Dec 31, 2004
    risk 0.05cvss epss 0.28

    Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

  • CVE-2004-2524Dec 31, 2004
    risk 0.00cvss epss 0.01

    clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in…

  • CVE-2004-2525Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

  • CVE-2004-2526Dec 31, 2004
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

  • CVE-2004-2527Dec 31, 2004
    risk 0.00cvss epss 0.01

    The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to…

  • CVE-2004-2528Dec 31, 2004
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.

  • CVE-2004-2529Dec 31, 2004
    risk 0.00cvss epss 0.01

    Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.

  • CVE-2004-2530Dec 31, 2004
    risk 0.03cvss epss 0.06

    Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.

  • CVE-2004-2531Dec 31, 2004
    risk 0.00cvss epss 0.01

    X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.

  • CVE-2004-2532Dec 31, 2004
    risk 0.03cvss epss 0.02

    Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then…

  • CVE-2004-2533Dec 31, 2004
    risk 0.00cvss epss 0.05

    Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

  • CVE-2004-2534Dec 31, 2004
    risk 0.04cvss epss 0.07

    Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

  • CVE-2004-2535Dec 31, 2004
    risk 0.00cvss epss 0.00

    The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.

  • CVE-2004-2536Dec 31, 2004
    risk 0.00cvss epss 0.00

    The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other processes to access…

  • CVE-2004-2537Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

  • CVE-2004-2538Dec 31, 2004
    risk 0.00cvss epss 0.03

    Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.

  • CVE-2004-2539Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID

  • CVE-2004-2540Dec 31, 2004
    risk 0.00cvss epss 0.01

    readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.

  • CVE-2004-2541Dec 31, 2004
    risk 0.00cvss epss 0.02

    Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.

  • CVE-2004-2542Dec 31, 2004
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Dynix (formerly known as epixtech) WebPAC allow remote attackers to execute arbitrary SQL commands via unknown attack vectors, resulting in an ability to execute stored procedures, bypass login authentication, and cause an unspecified…

  • CVE-2004-2543Dec 31, 2004
    risk 0.00cvss epss 0.01

    Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because…

  • CVE-2004-2544Dec 31, 2004
    risk 0.00cvss epss 0.00

    Admin Console in Secure Computing Corporation Sidewinder G2 6.1.0.01 exports private keys when exporting firewall certificates, which might allow attackers to obtain sensitive information.

  • CVE-2004-2545Dec 31, 2004
    risk 0.00cvss epss 0.01

    Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system…

  • CVE-2004-2546Dec 31, 2004
    risk 0.00cvss epss 0.01

    Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).

  • CVE-2004-2547Dec 31, 2004
    risk 0.04cvss epss 0.14

    NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

  • CVE-2004-2548Dec 31, 2004
    risk 0.04cvss epss 0.12

    Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the…

  • CVE-2004-2549Dec 31, 2004
    risk 0.04cvss epss 0.08

    Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP…

  • CVE-2004-2550Dec 31, 2004
    risk 0.00cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.

  • CVE-2004-2551Dec 31, 2004
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in…

  • CVE-2004-2552Dec 31, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue…

  • CVE-2004-2553Dec 31, 2004
    risk 0.00cvss epss 0.01

    The Ignition Project ignitionServer 0.1.2 through 0.1.2-R2 allows remote authenticated users with local IRC operator privileges to obtain global IRC operator privileges by using the unofficial umode command with the +ORD argument.

  • CVE-2004-2554Dec 31, 2004
    risk 0.00cvss epss 0.00

    Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.

  • CVE-2004-2555Dec 31, 2004
    risk 0.03cvss epss 0.00

    Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password…

  • CVE-2004-2556Dec 31, 2004
    risk 0.00cvss epss 0.01

    NetGear WG602 (aka WG602v1) Wireless Access Point firmware 1.04.0 and 1.5.67 has a hardcoded account of username "super" and password "5777364", which allows remote attackers to modify the configuration.

  • CVE-2004-2557Dec 31, 2004
    risk 0.00cvss epss 0.01

    NetGear WG602 (aka WG602v1) Wireless Access Point 1.7.14 has a hardcoded account of username "superman" and password "21241036", which allows remote attackers to modify the configuration.

  • CVE-2004-2558Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace…

  • CVE-2004-2559Dec 31, 2004
    risk 0.00cvss epss 0.01

    DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.

  • CVE-2004-2560Dec 31, 2004
    risk 0.00cvss epss 0.02

    DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".

  • CVE-2004-2561Dec 31, 2004
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.