| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2614 | 0.04 | — | 0.14 | Dec 31, 2004 | Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | |||
| CVE-2004-2615 | 0.00 | — | 0.00 | Dec 31, 2004 | The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact. | |||
| CVE-2004-2616 | 0.00 | — | 0.00 | Dec 31, 2004 | The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message. | |||
| CVE-2004-2617 | 0.04 | — | 0.09 | Dec 31, 2004 | Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI. | |||
| CVE-2004-2618 | 0.03 | — | 0.02 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash). | |||
| CVE-2004-2619 | 0.00 | — | 0.00 | Dec 31, 2004 | ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted. | |||
| CVE-2004-2620 | 0.00 | — | 0.00 | Dec 31, 2004 | The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow. | |||
| CVE-2004-2621 | 0.00 | — | 0.00 | Dec 31, 2004 | Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle… | |||
| CVE-2004-2622 | 0.00 | — | 0.02 | Dec 31, 2004 | AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access. | |||
| CVE-2004-2623 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter." | |||
| CVE-2004-2624 | 0.00 | — | 0.00 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter. | |||
| CVE-2004-2625 | 0.03 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag. | |||
| CVE-2004-2626 | 0.03 | — | 0.02 | Dec 31, 2004 | GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message. | |||
| CVE-2004-2627 | 0.01 | — | 0.11 | Dec 31, 2004 | Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code. | |||
| CVE-2004-2628 | 0.04 | — | 0.08 | Dec 31, 2004 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). | |||
| CVE-2004-2629 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as… | |||
| CVE-2004-2630 | 0.00 | — | 0.02 | Dec 31, 2004 | The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors. | |||
| CVE-2004-2631 | 0.04 | — | 0.14 | Dec 31, 2004 | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. | |||
| CVE-2004-2632 | 0.00 | — | 0.03 | Dec 31, 2004 | phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. | |||
| CVE-2004-2633 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users via unknown vectors. | |||
| CVE-2004-2634 | 0.00 | — | 0.00 | Dec 31, 2004 | The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors. | |||
| CVE-2004-2635 | 0.00 | — | 0.02 | Dec 31, 2004 | An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method. | |||
| CVE-2004-2636 | 0.03 | — | 0.04 | Dec 31, 2004 | TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL. | |||
| CVE-2004-2637 | 0.00 | — | 0.01 | Dec 31, 2004 | The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions. | |||
| CVE-2004-2638 | 0.00 | — | 0.01 | Dec 31, 2004 | The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value. | |||
| CVE-2004-2639 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors. | |||
| CVE-2004-2640 | 0.04 | — | 0.10 | Dec 31, 2004 | Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter. | |||
| CVE-2004-2641 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set. | |||
| CVE-2004-2642 | 0.00 | — | 0.01 | Dec 31, 2004 | Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender. | |||
| CVE-2004-2643 | 0.00 | — | 0.00 | Dec 31, 2004 | Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive. | |||
| CVE-2004-2644 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags. | |||
| CVE-2004-2645 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures." | |||
| CVE-2004-2646 | 0.04 | — | 0.11 | Dec 31, 2004 | The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null. | |||
| CVE-2004-2647 | — | 0.04 | — | 0.11 | Dec 31, 2004 | Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user. | ||
| CVE-2004-2648 | 0.00 | — | 0.00 | Dec 31, 2004 | FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file. | |||
| CVE-2004-2649 | 0.04 | — | 0.09 | Dec 31, 2004 | Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as " ") in the middle of the URL. | |||
| CVE-2004-2650 | 0.00 | — | 0.00 | Dec 31, 2004 | Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak. | |||
| CVE-2004-2651 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html. | |||
| CVE-2004-2652 | 0.05 | — | 0.23 | Dec 31, 2004 | The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference. | |||
| CVE-2004-2653 | 0.00 | — | 0.00 | Dec 31, 2004 | Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp. | |||
| CVE-2004-2654 | 0.00 | — | 0.01 | Dec 31, 2004 | The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that… | |||
| CVE-2004-2655 | 0.00 | — | 0.01 | Dec 31, 2004 | rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen. | |||
| CVE-2004-2656 | 0.00 | — | 0.01 | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in… | |||
| CVE-2004-2657 | 0.00 | — | 0.00 | Dec 31, 2004 | Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved… | |||
| CVE-2004-2658 | 0.00 | — | 0.00 | Dec 31, 2004 | resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types. | |||
| CVE-2004-2659 | 0.00 | — | 0.00 | Dec 31, 2004 | Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the… | |||
| CVE-2004-2660 | 0.00 | — | 0.00 | Dec 31, 2004 | Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory consumption) via certain O_DIRECT (direct IO) write requests. | |||
| CVE-2004-2661 | 0.00 | — | 0.00 | Dec 31, 2004 | Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code). | |||
| CVE-2004-2662 | 0.00 | — | 0.01 | Dec 31, 2004 | Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources. | |||
| CVE-2004-2663 | 0.00 | — | 0.02 | Dec 31, 2004 | The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder. |
- CVE-2004-2614Dec 31, 2004risk 0.04cvss —epss 0.14
Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
- CVE-2004-2615Dec 31, 2004risk 0.00cvss —epss 0.00
The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.
- CVE-2004-2616Dec 31, 2004risk 0.00cvss —epss 0.00
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.
- CVE-2004-2617Dec 31, 2004risk 0.04cvss —epss 0.09
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
- CVE-2004-2618Dec 31, 2004risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).
- CVE-2004-2619Dec 31, 2004risk 0.00cvss —epss 0.00
ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.
- CVE-2004-2620Dec 31, 2004risk 0.00cvss —epss 0.00
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.
- CVE-2004-2621Dec 31, 2004risk 0.00cvss —epss 0.00
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle…
- CVE-2004-2622Dec 31, 2004risk 0.00cvss —epss 0.02
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
- CVE-2004-2623Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter."
- CVE-2004-2624Dec 31, 2004risk 0.00cvss —epss 0.00
Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter.
- CVE-2004-2625Dec 31, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.
- CVE-2004-2626Dec 31, 2004risk 0.03cvss —epss 0.02
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.
- CVE-2004-2627Dec 31, 2004risk 0.01cvss —epss 0.11
Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code.
- CVE-2004-2628Dec 31, 2004risk 0.04cvss —epss 0.08
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
- CVE-2004-2629Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as…
- CVE-2004-2630Dec 31, 2004risk 0.00cvss —epss 0.02
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
- CVE-2004-2631Dec 31, 2004risk 0.04cvss —epss 0.14
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.
- CVE-2004-2632Dec 31, 2004risk 0.00cvss —epss 0.03
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.
- CVE-2004-2633Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users via unknown vectors.
- CVE-2004-2634Dec 31, 2004risk 0.00cvss —epss 0.00
The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.
- CVE-2004-2635Dec 31, 2004risk 0.00cvss —epss 0.02
An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.
- CVE-2004-2636Dec 31, 2004risk 0.03cvss —epss 0.04
TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.
- CVE-2004-2637Dec 31, 2004risk 0.00cvss —epss 0.01
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.
- CVE-2004-2638Dec 31, 2004risk 0.00cvss —epss 0.01
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
- CVE-2004-2639Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.
- CVE-2004-2640Dec 31, 2004risk 0.04cvss —epss 0.10
Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.
- CVE-2004-2641Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.
- CVE-2004-2642Dec 31, 2004risk 0.00cvss —epss 0.01
Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.
- CVE-2004-2643Dec 31, 2004risk 0.00cvss —epss 0.00
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.
- CVE-2004-2644Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.
- CVE-2004-2645Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."
- CVE-2004-2646Dec 31, 2004risk 0.04cvss —epss 0.11
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.
- CVE-2004-2647Dec 31, 2004risk 0.04cvss —epss 0.11
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.
- CVE-2004-2648Dec 31, 2004risk 0.00cvss —epss 0.00
FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.
- CVE-2004-2649Dec 31, 2004risk 0.04cvss —epss 0.09
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as " ") in the middle of the URL.
- CVE-2004-2650Dec 31, 2004risk 0.00cvss —epss 0.00
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
- CVE-2004-2651Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.
- CVE-2004-2652Dec 31, 2004risk 0.05cvss —epss 0.23
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
- CVE-2004-2653Dec 31, 2004risk 0.00cvss —epss 0.00
Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.
- CVE-2004-2654Dec 31, 2004risk 0.00cvss —epss 0.01
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that…
- CVE-2004-2655Dec 31, 2004risk 0.00cvss —epss 0.01
rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.
- CVE-2004-2656Dec 31, 2004risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in…
- CVE-2004-2657Dec 31, 2004risk 0.00cvss —epss 0.00
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved…
- CVE-2004-2658Dec 31, 2004risk 0.00cvss —epss 0.00
resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.
- CVE-2004-2659Dec 31, 2004risk 0.00cvss —epss 0.00
Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the…
- CVE-2004-2660Dec 31, 2004risk 0.00cvss —epss 0.00
Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory consumption) via certain O_DIRECT (direct IO) write requests.
- CVE-2004-2661Dec 31, 2004risk 0.00cvss —epss 0.00
Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).
- CVE-2004-2662Dec 31, 2004risk 0.00cvss —epss 0.01
Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources.
- CVE-2004-2663Dec 31, 2004risk 0.00cvss —epss 0.02
The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.