VYPR

CVEs

378,446 total · page 7366 of 7,569

  • CVE-2004-1516Dec 31, 2004
    risk 0.00cvss epss 0.02

    CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

  • CVE-2004-1517Dec 31, 2004
    risk 0.00cvss epss 0.02

    Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.

  • CVE-2004-1518Dec 31, 2004
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.

  • CVE-2004-1519Dec 31, 2004
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

  • CVE-2004-1520Dec 31, 2004
    risk 0.10cvss epss 0.89

    Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.

  • CVE-2004-1521Dec 31, 2004
    risk 0.03cvss epss 0.02

    Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

  • CVE-2004-1522Dec 31, 2004
    risk 0.00cvss epss 0.02

    Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.

  • CVE-2004-1523Dec 31, 2004
    risk 0.00cvss epss 0.02

    Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.

  • CVE-2004-1524Dec 31, 2004
    risk 0.00cvss epss 0.02

    Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.

  • CVE-2004-1525Dec 31, 2004
    risk 0.00cvss epss 0.02

    Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

  • CVE-2004-1526Dec 31, 2004
    risk 0.00cvss epss 0.01

    Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.

  • CVE-2004-1527Dec 31, 2004
    risk 0.00cvss epss 0.01

    Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows…

  • CVE-2004-1528Dec 31, 2004
    risk 0.00cvss epss 0.02

    The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.

  • CVE-2004-1529Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.

  • CVE-2004-1530Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.

  • CVE-2004-1531Dec 31, 2004
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

  • CVE-2004-1532Dec 31, 2004
    risk 0.00cvss epss 0.02

    AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.

  • CVE-2004-1533Dec 31, 2004
    risk 0.04cvss epss 0.08

    Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.

  • CVE-2004-1534Dec 31, 2004
    risk 0.00cvss epss 0.02

    ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.

  • CVE-2004-1535Dec 31, 2004
    risk 0.04cvss epss 0.06

    PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-1536Dec 31, 2004
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2004-1537Dec 31, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.

  • CVE-2004-1538Dec 31, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2004-1539Dec 31, 2004
    risk 0.03cvss epss 0.03

    Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.

  • CVE-2004-1540Dec 31, 2004
    risk 0.04cvss epss 0.07

    ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

  • CVE-2004-1541Dec 31, 2004
    risk 0.00cvss epss 0.02

    SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.

  • CVE-2004-1542Dec 31, 2004
    risk 0.03cvss epss 0.03

    Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.

  • CVE-2004-1543Dec 31, 2004
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

  • CVE-2004-1544Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.

  • CVE-2004-1545Dec 31, 2004
    risk 0.00cvss epss 0.03

    UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.

  • CVE-2004-1546Dec 31, 2004
    risk 0.05cvss epss 0.31

    Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.

  • CVE-2004-1547Dec 31, 2004
    risk 0.00cvss epss 0.02

    The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.

  • CVE-2004-1548Dec 31, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.

  • CVE-2004-1549Dec 31, 2004
    risk 0.00cvss epss 0.02

    The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.

  • CVE-2004-1550Dec 31, 2004
    risk 0.04cvss epss 0.19

    Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

  • CVE-2004-1551Dec 31, 2004
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.

  • CVE-2004-1552Dec 31, 2004
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.

  • CVE-2004-1553Dec 31, 2004
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves…

  • CVE-2004-1554Dec 31, 2004
    risk 0.04cvss epss 0.07

    PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-1555Dec 31, 2004
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail…

  • CVE-2004-1556Dec 31, 2004
    risk 0.00cvss epss 0.02

    MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.

  • CVE-2004-1557Dec 31, 2004
    risk 0.00cvss epss 0.02

    MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.

  • CVE-2004-1558Dec 31, 2004
    risk 0.09cvss epss 0.71

    Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.

  • CVE-2004-1559Dec 31, 2004
    risk 0.04cvss epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle,…

  • CVE-2004-1560Dec 31, 2004
    risk 0.05cvss epss 0.26

    Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.

  • CVE-2004-1561Dec 31, 2004
    risk 0.09cvss epss 0.78

    Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.

  • CVE-2004-1562Dec 31, 2004
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

  • CVE-2004-1563Dec 31, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

  • CVE-2004-1564Dec 31, 2004
    risk 0.03cvss epss 0.06

    CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

  • CVE-2004-1565Dec 31, 2004
    risk 0.00cvss epss 0.02

    list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.