| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2435 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts. | |||
| CVE-2004-2436 | 0.00 | — | 0.00 | Dec 31, 2004 | Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | |||
| CVE-2004-2437 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php. | |||
| CVE-2004-2438 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field. | |||
| CVE-2004-2439 | 0.00 | — | 0.02 | Dec 31, 2004 | The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware. | |||
| CVE-2004-2440 | 0.00 | — | 0.00 | Dec 31, 2004 | Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users. | |||
| CVE-2004-2441 | 0.00 | — | 0.02 | Dec 31, 2004 | Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue." | |||
| CVE-2004-2442 | 0.04 | — | 0.11 | Dec 31, 2004 | Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers… | |||
| CVE-2004-2443 | 0.04 | — | 0.09 | Dec 31, 2004 | Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php. | |||
| CVE-2004-2444 | 0.03 | — | 0.04 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |||
| CVE-2004-2445 | 0.04 | — | 0.08 | Dec 31, 2004 | Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter. | |||
| CVE-2004-2446 | 0.00 | — | 0.02 | Dec 31, 2004 | Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors. | |||
| CVE-2004-2447 | 0.03 | — | 0.03 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6)… | |||
| CVE-2004-2448 | 0.00 | — | 0.01 | Dec 31, 2004 | S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name. | |||
| CVE-2004-2449 | 0.03 | — | 0.06 | Dec 31, 2004 | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram. | |||
| CVE-2004-2450 | 0.00 | — | 0.02 | Dec 31, 2004 | The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information. | |||
| CVE-2004-2451 | 0.03 | — | 0.02 | Dec 31, 2004 | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. | |||
| CVE-2004-2452 | 0.00 | — | 0.02 | Dec 31, 2004 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |||
| CVE-2004-2453 | 0.00 | — | 0.02 | Dec 31, 2004 | Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors. | |||
| CVE-2004-2454 | 0.00 | — | 0.00 | Dec 31, 2004 | aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hotlog.htm and (2) config.xml. | |||
| CVE-2004-2455 | 0.00 | — | 0.02 | Dec 31, 2004 | Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file. | |||
| CVE-2004-2456 | 0.03 | — | 0.03 | Dec 31, 2004 | SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action. | |||
| CVE-2004-2457 | — | 0.00 | — | 0.02 | Dec 31, 2004 | Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic. | ||
| CVE-2004-2458 | 0.00 | — | 0.01 | Dec 31, 2004 | Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories. | |||
| CVE-2004-2459 | 0.00 | — | 0.01 | Dec 31, 2004 | Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table. | |||
| CVE-2004-2460 | 0.00 | — | 0.02 | Dec 31, 2004 | Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list. | |||
| CVE-2004-2461 | 0.00 | — | 0.03 | Dec 31, 2004 | Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code. | |||
| CVE-2004-2462 | 0.00 | — | 0.00 | Dec 31, 2004 | cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file. | |||
| CVE-2004-2463 | 0.00 | — | 0.04 | Dec 31, 2004 | Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request. | |||
| CVE-2004-2464 | 0.03 | — | 0.04 | Dec 31, 2004 | Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected. | |||
| CVE-2004-2465 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |||
| CVE-2004-2466 | 0.09 | — | 0.75 | Dec 31, 2004 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected. | |||
| CVE-2004-2467 | 0.00 | — | 0.03 | Dec 31, 2004 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash). | |||
| CVE-2004-2468 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |||
| CVE-2004-2469 | 0.00 | — | 0.01 | Dec 31, 2004 | Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations. | |||
| CVE-2004-2470 | 0.00 | — | 0.02 | Dec 31, 2004 | Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins. | |||
| CVE-2004-2471 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |||
| CVE-2004-2472 | 0.00 | — | 0.02 | Dec 31, 2004 | Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro. | |||
| CVE-2004-2473 | 0.00 | — | 0.00 | Dec 31, 2004 | wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |||
| CVE-2004-2474 | 0.00 | — | 0.01 | Dec 31, 2004 | SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php. | |||
| CVE-2004-2475 | 0.03 | — | 0.03 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege… | |||
| CVE-2004-2476 | 0.01 | — | 0.09 | Dec 31, 2004 | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source. | |||
| CVE-2004-2477 | 0.00 | — | 0.00 | Dec 31, 2004 | DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe. | |||
| CVE-2004-2478 | 0.00 | — | 0.02 | Dec 31, 2004 | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot)… | |||
| CVE-2004-2479 | 0.00 | — | 0.02 | Dec 31, 2004 | Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages. | |||
| CVE-2004-2480 | 0.03 | — | 0.03 | Dec 31, 2004 | Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer. | |||
| CVE-2004-2481 | 0.00 | — | 0.02 | Dec 31, 2004 | MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command. | |||
| CVE-2004-2482 | 0.01 | — | 0.13 | Dec 31, 2004 | Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in… | |||
| CVE-2004-2483 | 0.00 | — | 0.02 | Dec 31, 2004 | Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss). | |||
| CVE-2004-2484 | 0.00 | — | 0.01 | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php. |
- CVE-2004-2435Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.
- CVE-2004-2436Dec 31, 2004risk 0.00cvss —epss 0.00
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.
- CVE-2004-2437Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.
- CVE-2004-2438Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.
- CVE-2004-2439Dec 31, 2004risk 0.00cvss —epss 0.02
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
- CVE-2004-2440Dec 31, 2004risk 0.00cvss —epss 0.00
Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users.
- CVE-2004-2441Dec 31, 2004risk 0.00cvss —epss 0.02
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."
- CVE-2004-2442Dec 31, 2004risk 0.04cvss —epss 0.11
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers…
- CVE-2004-2443Dec 31, 2004risk 0.04cvss —epss 0.09
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
- CVE-2004-2444Dec 31, 2004risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
- CVE-2004-2445Dec 31, 2004risk 0.04cvss —epss 0.08
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.
- CVE-2004-2446Dec 31, 2004risk 0.00cvss —epss 0.02
Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors.
- CVE-2004-2447Dec 31, 2004risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6)…
- CVE-2004-2448Dec 31, 2004risk 0.00cvss —epss 0.01
S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name.
- CVE-2004-2449Dec 31, 2004risk 0.03cvss —epss 0.06
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.
- CVE-2004-2450Dec 31, 2004risk 0.00cvss —epss 0.02
The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information.
- CVE-2004-2451Dec 31, 2004risk 0.03cvss —epss 0.02
Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug.
- CVE-2004-2452Dec 31, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.
- CVE-2004-2453Dec 31, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors.
- CVE-2004-2454Dec 31, 2004risk 0.00cvss —epss 0.00
aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hotlog.htm and (2) config.xml.
- CVE-2004-2455Dec 31, 2004risk 0.00cvss —epss 0.02
Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.
- CVE-2004-2456Dec 31, 2004risk 0.03cvss —epss 0.03
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.
- CVE-2004-2457Dec 31, 2004risk 0.00cvss —epss 0.02
Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.
- CVE-2004-2458Dec 31, 2004risk 0.00cvss —epss 0.01
Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.
- CVE-2004-2459Dec 31, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.
- CVE-2004-2460Dec 31, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.
- CVE-2004-2461Dec 31, 2004risk 0.00cvss —epss 0.03
Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.
- CVE-2004-2462Dec 31, 2004risk 0.00cvss —epss 0.00
cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file.
- CVE-2004-2463Dec 31, 2004risk 0.00cvss —epss 0.04
Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.
- CVE-2004-2464Dec 31, 2004risk 0.03cvss —epss 0.04
Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.
- CVE-2004-2465Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
- CVE-2004-2466Dec 31, 2004risk 0.09cvss —epss 0.75
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
- CVE-2004-2467Dec 31, 2004risk 0.00cvss —epss 0.03
chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).
- CVE-2004-2468Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
- CVE-2004-2469Dec 31, 2004risk 0.00cvss —epss 0.01
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
- CVE-2004-2470Dec 31, 2004risk 0.00cvss —epss 0.02
Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.
- CVE-2004-2471Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
- CVE-2004-2472Dec 31, 2004risk 0.00cvss —epss 0.02
Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.
- CVE-2004-2473Dec 31, 2004risk 0.00cvss —epss 0.00
wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
- CVE-2004-2474Dec 31, 2004risk 0.00cvss —epss 0.01
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
- CVE-2004-2475Dec 31, 2004risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege…
- CVE-2004-2476Dec 31, 2004risk 0.01cvss —epss 0.09
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
- CVE-2004-2477Dec 31, 2004risk 0.00cvss —epss 0.00
DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.
- CVE-2004-2478Dec 31, 2004risk 0.00cvss —epss 0.02
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot)…
- CVE-2004-2479Dec 31, 2004risk 0.00cvss —epss 0.02
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
- CVE-2004-2480Dec 31, 2004risk 0.03cvss —epss 0.03
Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.
- CVE-2004-2481Dec 31, 2004risk 0.00cvss —epss 0.02
MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.
- CVE-2004-2482Dec 31, 2004risk 0.01cvss —epss 0.13
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in…
- CVE-2004-2483Dec 31, 2004risk 0.00cvss —epss 0.02
Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).
- CVE-2004-2484Dec 31, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.