VYPR

CVEs

343,710 total · page 6706 of 6,875

  • CVE-2003-0906Jun 1, 2004
    risk 0.02cvss epss 0.25

    Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.

  • CVE-2003-0907Jun 1, 2004
    risk 0.02cvss epss 0.22

    Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.

  • CVE-2003-0908Jun 1, 2004
    risk 0.05cvss epss 0.27

    The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using…

  • CVE-2003-0909Jun 1, 2004
    risk 0.02cvss epss 0.21

    Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

  • CVE-2003-0910Jun 1, 2004
    risk 0.05cvss epss 0.28

    The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points…

  • CVE-2004-0109Jun 1, 2004
    risk 0.00cvss epss 0.01

    Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

  • CVE-2004-0116Jun 1, 2004
    risk 0.03cvss epss 0.37

    An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

  • CVE-2004-0117Jun 1, 2004
    risk 0.02cvss epss 0.26

    Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

  • CVE-2004-0118Jun 1, 2004
    risk 0.02cvss epss 0.22

    The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.

  • CVE-2004-0119HigJun 1, 2004
    risk 0.52cvss 7.5epss 0.40

    The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during…

  • CVE-2004-0120Jun 1, 2004
    risk 0.07cvss epss 0.56

    The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.

  • CVE-2004-0123Jun 1, 2004
    risk 0.02cvss epss 0.30

    Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2004-0124Jun 1, 2004
    risk 0.02cvss epss 0.21

    The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."

  • CVE-2004-0133Jun 1, 2004
    risk 0.00cvss epss 0.00

    The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.

  • CVE-2004-0155Jun 1, 2004
    risk 0.00cvss epss 0.04

    The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid,…

  • CVE-2004-0156Jun 1, 2004
    risk 0.00cvss epss 0.04

    Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.

  • CVE-2004-0157Jun 1, 2004
    risk 0.00cvss epss 0.00

    x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.

  • CVE-2004-0177Jun 1, 2004
    risk 0.00cvss epss 0.03

    The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by…

  • CVE-2004-0178Jun 1, 2004
    risk 0.00cvss epss 0.00

    The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.

  • CVE-2004-0179Jun 1, 2004
    risk 0.04cvss epss 0.11

    Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

  • CVE-2004-0180Jun 1, 2004
    risk 0.00cvss epss 0.02

    The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

  • CVE-2004-0181Jun 1, 2004
    risk 0.00cvss epss 0.00

    The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.

  • CVE-2004-0182Jun 1, 2004
    risk 0.00cvss epss 0.01

    Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

  • CVE-2004-0197Jun 1, 2004
    risk 0.02cvss epss 0.26

    Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.

  • CVE-2004-0385Jun 1, 2004
    risk 0.01cvss epss 0.15

    Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle…

  • CVE-2004-0387Jun 1, 2004
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.

  • CVE-2004-0388Jun 1, 2004
    risk 0.00cvss epss 0.01

    The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2004-0389HigJun 1, 2004
    risk 0.56cvss 7.5epss 0.52

    RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.

  • CVE-2004-0391Jun 1, 2004
    risk 0.00cvss epss 0.05

    Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

  • CVE-2004-0403Jun 1, 2004
    risk 0.00cvss epss 0.03

    Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.

  • CVE-2004-0405Jun 1, 2004
    risk 0.00cvss epss 0.02

    CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

  • CVE-2004-0407Jun 1, 2004
    risk 0.00cvss epss 0.02

    The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.

  • CVE-2004-0409Jun 1, 2004
    risk 0.04cvss epss 0.09

    Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

  • CVE-2004-2044Jun 1, 2004
    risk 0.04cvss epss 0.11

    PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to…

  • CVE-2004-2038May 29, 2004
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.

  • CVE-2004-2039May 29, 2004
    risk 0.00cvss epss 0.02

    e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.

  • CVE-2004-2040May 29, 2004
    risk 0.03cvss epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to…

  • CVE-2004-2041May 29, 2004
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-2042May 29, 2004
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.

  • CVE-2004-2036May 28, 2004
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.

  • CVE-2004-2033May 26, 2004
    risk 0.03cvss epss 0.04

    Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

  • CVE-2004-2035May 26, 2004
    risk 0.03cvss epss 0.04

    MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.

  • CVE-2004-2135May 26, 2004
    risk 0.03cvss epss 0.01

    cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.

  • CVE-2004-2032May 24, 2004
    risk 0.03cvss epss 0.03

    Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.

  • CVE-2004-2029May 22, 2004
    risk 0.03cvss epss 0.04

    The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.

  • CVE-2004-2030May 22, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.

  • CVE-2004-2028May 21, 2004
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.

  • CVE-2004-2031May 21, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.

  • CVE-2004-1354May 14, 2004
    risk 0.00cvss epss 0.04

    The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a…

  • CVE-2004-2027May 10, 2004
    risk 0.00cvss epss 0.02

    Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.