| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0263 | 0.00 | — | 0.02 | Nov 23, 2004 | PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information. | |||
| CVE-2004-0264 | 0.03 | — | 0.06 | Nov 23, 2004 | palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. | |||
| CVE-2004-0265 | 0.04 | — | 0.10 | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules. | |||
| CVE-2004-0266 | 0.03 | — | 0.00 | Nov 23, 2004 | SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter. | |||
| CVE-2004-0267 | 0.00 | — | 0.00 | Nov 23, 2004 | The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp. | |||
| CVE-2004-0268 | 0.03 | — | 0.05 | Nov 23, 2004 | Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server. | |||
| CVE-2004-0269 | 0.03 | — | 0.00 | Nov 23, 2004 | SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module. | |||
| CVE-2004-0270 | 0.04 | — | 0.11 | Nov 23, 2004 | libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program. | |||
| CVE-2004-0271 | 0.03 | — | 0.04 | Nov 23, 2004 | Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4)… | |||
| CVE-2004-0272 | 0.00 | — | 0.01 | Nov 23, 2004 | SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | |||
| CVE-2004-0273 | 0.00 | — | 0.00 | Nov 23, 2004 | Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file. | |||
| CVE-2004-0274 | 0.00 | — | 0.01 | Nov 23, 2004 | Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities. | |||
| CVE-2004-0275 | 0.03 | — | 0.00 | Nov 23, 2004 | SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | |||
| CVE-2004-0276 | 0.04 | — | 0.09 | Nov 23, 2004 | The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field. | |||
| CVE-2004-0277 | 0.04 | — | 0.08 | Nov 23, 2004 | Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. | |||
| CVE-2004-0278 | 0.00 | — | 0.01 | Nov 23, 2004 | Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet… | |||
| CVE-2004-0279 | 0.00 | — | 0.00 | Nov 23, 2004 | AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log. | |||
| CVE-2004-0280 | 0.00 | — | 0.01 | Nov 23, 2004 | Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20. | |||
| CVE-2004-0281 | 0.04 | — | 0.12 | Nov 23, 2004 | Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows. | |||
| CVE-2004-0282 | 0.03 | — | 0.04 | Nov 23, 2004 | Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server. | |||
| CVE-2004-0283 | 0.00 | — | 0.00 | Nov 23, 2004 | Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort. | |||
| CVE-2004-0284 | 0.01 | — | 0.09 | Nov 23, 2004 | Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name. | |||
| CVE-2004-0285 | Cri | 0.69 | 9.8 | 0.30 | Nov 23, 2004 | PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter. | ||
| CVE-2004-0286 | 0.04 | — | 0.12 | Nov 23, 2004 | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username. | |||
| CVE-2004-0287 | 0.03 | — | 0.04 | Nov 23, 2004 | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | |||
| CVE-2004-0288 | 0.00 | — | 0.05 | Nov 23, 2004 | Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document. | |||
| CVE-2004-0289 | 0.00 | — | 0.00 | Nov 23, 2004 | Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter. | |||
| CVE-2004-0290 | 0.03 | — | 0.05 | Nov 23, 2004 | Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields. | |||
| CVE-2004-0291 | 0.03 | — | 0.00 | Nov 23, 2004 | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | |||
| CVE-2004-0292 | 0.04 | — | 0.10 | Nov 23, 2004 | Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | |||
| CVE-2004-0293 | 0.03 | — | 0.05 | Nov 23, 2004 | Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi. | |||
| CVE-2004-0294 | 0.00 | — | 0.02 | Nov 23, 2004 | YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack. | |||
| CVE-2004-0295 | 0.03 | — | 0.05 | Nov 23, 2004 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection. | |||
| CVE-2004-0296 | 0.00 | — | 0.01 | Nov 23, 2004 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection. | |||
| CVE-2004-0297 | 0.08 | — | 0.62 | Nov 23, 2004 | Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length. | |||
| CVE-2004-0298 | 0.03 | — | 0.05 | Nov 23, 2004 | CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter. | |||
| CVE-2004-0299 | 0.03 | — | 0.00 | Nov 23, 2004 | Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters. | |||
| CVE-2004-0300 | 0.03 | — | 0.03 | Nov 23, 2004 | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id… | |||
| CVE-2004-0301 | 0.03 | — | 0.01 | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | |||
| CVE-2004-0302 | 0.04 | — | 0.09 | Nov 23, 2004 | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | |||
| CVE-2004-0303 | 0.04 | — | 0.09 | Nov 23, 2004 | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using… | |||
| CVE-2004-0304 | 0.03 | — | 0.01 | Nov 23, 2004 | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | |||
| CVE-2004-0305 | 0.03 | — | 0.04 | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | |||
| CVE-2004-0306 | 0.00 | — | 0.01 | Nov 23, 2004 | Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1… | |||
| CVE-2004-0307 | 0.00 | — | 0.01 | Nov 23, 2004 | Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead. | |||
| CVE-2004-0309 | 0.03 | — | 0.32 | Nov 23, 2004 | Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument. | |||
| CVE-2004-0310 | 0.00 | — | 0.01 | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url. | |||
| CVE-2004-0311 | 0.00 | — | 0.02 | Nov 23, 2004 | American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access. | |||
| CVE-2004-0312 | 0.03 | — | 0.04 | Nov 23, 2004 | Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2. | |||
| CVE-2004-0313 | 0.09 | — | 0.78 | Nov 23, 2004 | Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name. |
- CVE-2004-0263Nov 23, 2004risk 0.00cvss —epss 0.02
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
- CVE-2004-0264Nov 23, 2004risk 0.03cvss —epss 0.06
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.
- CVE-2004-0265Nov 23, 2004risk 0.04cvss —epss 0.10
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.
- CVE-2004-0266Nov 23, 2004risk 0.03cvss —epss 0.00
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.
- CVE-2004-0267Nov 23, 2004risk 0.00cvss —epss 0.00
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.
- CVE-2004-0268Nov 23, 2004risk 0.03cvss —epss 0.05
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.
- CVE-2004-0269Nov 23, 2004risk 0.03cvss —epss 0.00
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
- CVE-2004-0270Nov 23, 2004risk 0.04cvss —epss 0.11
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.
- CVE-2004-0271Nov 23, 2004risk 0.03cvss —epss 0.04
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4)…
- CVE-2004-0272Nov 23, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.
- CVE-2004-0273Nov 23, 2004risk 0.00cvss —epss 0.00
Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.
- CVE-2004-0274Nov 23, 2004risk 0.00cvss —epss 0.01
Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.
- CVE-2004-0275Nov 23, 2004risk 0.03cvss —epss 0.00
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.
- CVE-2004-0276Nov 23, 2004risk 0.04cvss —epss 0.09
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.
- CVE-2004-0277Nov 23, 2004risk 0.04cvss —epss 0.08
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.
- CVE-2004-0278Nov 23, 2004risk 0.00cvss —epss 0.01
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet…
- CVE-2004-0279Nov 23, 2004risk 0.00cvss —epss 0.00
AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.
- CVE-2004-0280Nov 23, 2004risk 0.00cvss —epss 0.01
Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.
- CVE-2004-0281Nov 23, 2004risk 0.04cvss —epss 0.12
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.
- CVE-2004-0282Nov 23, 2004risk 0.03cvss —epss 0.04
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.
- CVE-2004-0283Nov 23, 2004risk 0.00cvss —epss 0.00
Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.
- CVE-2004-0284Nov 23, 2004risk 0.01cvss —epss 0.09
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
- risk 0.69cvss 9.8epss 0.30
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
- CVE-2004-0286Nov 23, 2004risk 0.04cvss —epss 0.12
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.
- CVE-2004-0287Nov 23, 2004risk 0.03cvss —epss 0.04
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
- CVE-2004-0288Nov 23, 2004risk 0.00cvss —epss 0.05
Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.
- CVE-2004-0289Nov 23, 2004risk 0.00cvss —epss 0.00
Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.
- CVE-2004-0290Nov 23, 2004risk 0.03cvss —epss 0.05
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.
- CVE-2004-0291Nov 23, 2004risk 0.03cvss —epss 0.00
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.
- CVE-2004-0292Nov 23, 2004risk 0.04cvss —epss 0.10
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
- CVE-2004-0293Nov 23, 2004risk 0.03cvss —epss 0.05
Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.
- CVE-2004-0294Nov 23, 2004risk 0.00cvss —epss 0.02
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
- CVE-2004-0295Nov 23, 2004risk 0.03cvss —epss 0.05
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.
- CVE-2004-0296Nov 23, 2004risk 0.00cvss —epss 0.01
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.
- CVE-2004-0297Nov 23, 2004risk 0.08cvss —epss 0.62
Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.
- CVE-2004-0298Nov 23, 2004risk 0.03cvss —epss 0.05
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.
- CVE-2004-0299Nov 23, 2004risk 0.03cvss —epss 0.00
Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.
- CVE-2004-0300Nov 23, 2004risk 0.03cvss —epss 0.03
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id…
- CVE-2004-0301Nov 23, 2004risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.
- CVE-2004-0302Nov 23, 2004risk 0.04cvss —epss 0.09
Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.
- CVE-2004-0303Nov 23, 2004risk 0.04cvss —epss 0.09
OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using…
- CVE-2004-0304Nov 23, 2004risk 0.03cvss —epss 0.01
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.
- CVE-2004-0305Nov 23, 2004risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.
- CVE-2004-0306Nov 23, 2004risk 0.00cvss —epss 0.01
Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1…
- CVE-2004-0307Nov 23, 2004risk 0.00cvss —epss 0.01
Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.
- CVE-2004-0309Nov 23, 2004risk 0.03cvss —epss 0.32
Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.
- CVE-2004-0310Nov 23, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.
- CVE-2004-0311Nov 23, 2004risk 0.00cvss —epss 0.02
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.
- CVE-2004-0312Nov 23, 2004risk 0.03cvss —epss 0.04
Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.
- CVE-2004-0313Nov 23, 2004risk 0.09cvss —epss 0.78
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.