VYPR

CVEs

378,267 total · page 7387 of 7,566

  • CVE-2004-0777Oct 20, 2004
    risk 0.04cvss epss 0.11

    Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.

  • CVE-2004-0778Oct 20, 2004
    risk 0.00cvss epss 0.02

    CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.

  • CVE-2004-0781Oct 20, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

  • CVE-2004-0782Oct 20, 2004
    risk 0.01cvss epss 0.09

    Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this…

  • CVE-2004-0783Oct 20, 2004
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was…

  • CVE-2004-0784Oct 20, 2004
    risk 0.00cvss epss 0.02

    The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.

  • CVE-2004-0785Oct 20, 2004
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly…

  • CVE-2004-0786Oct 20, 2004
    risk 0.02cvss epss 0.24

    The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.

  • CVE-2004-0787Oct 20, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.

  • CVE-2004-0788Oct 20, 2004
    risk 0.00cvss epss 0.06

    Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.

  • CVE-2004-0792Oct 20, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is disabled, allows attackers to read or write certain files.

  • CVE-2004-0793Oct 20, 2004
    risk 0.00cvss epss 0.01

    The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.

  • CVE-2004-0794Oct 20, 2004
    risk 0.00cvss epss 0.02

    Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.

  • CVE-2004-0795Oct 20, 2004
    risk 0.03cvss epss 0.02

    DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

  • CVE-2004-0796Oct 20, 2004
    risk 0.00cvss epss 0.02

    SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages.

  • CVE-2004-0797Oct 20, 2004
    risk 0.00cvss epss 0.00

    The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).

  • CVE-2004-0798Oct 20, 2004
    risk 0.08cvss epss 0.63

    Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.

  • CVE-2004-0799Oct 20, 2004
    risk 0.00cvss epss 0.06

    The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".

  • CVE-2004-1380Oct 20, 2004
    risk 0.03cvss epss 0.04

    Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."

  • CVE-2004-1381Oct 20, 2004
    risk 0.04cvss epss 0.07

    Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could…

  • CVE-2004-1619Oct 20, 2004
    risk 0.03cvss epss 0.05

    Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

  • CVE-2004-1353Oct 19, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.

  • CVE-2004-1618Oct 19, 2004
    risk 0.00cvss epss 0.02

    Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.

  • CVE-2004-1603MedOct 18, 2004
    risk 0.36cvss 5.5epss 0.02

    cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.

  • CVE-2004-1606Oct 18, 2004
    risk 0.00cvss epss 0.02

    slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.

  • CVE-2004-1607Oct 18, 2004
    risk 0.00cvss epss 0.02

    slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.

  • CVE-2004-1608Oct 18, 2004
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.

  • CVE-2004-1609Oct 18, 2004
    risk 0.00cvss epss 0.02

    SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.

  • CVE-2004-1610Oct 18, 2004
    risk 0.00cvss epss 0.02

    SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.

  • CVE-2004-1611Oct 18, 2004
    risk 0.00cvss epss 0.02

    SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password…

  • CVE-2004-1612Oct 18, 2004
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.

  • CVE-2004-1613Oct 18, 2004
    risk 0.00cvss epss 0.02

    Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated…

  • CVE-2004-1614Oct 18, 2004
    risk 0.00cvss epss 0.01

    Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.

  • CVE-2004-1615Oct 18, 2004
    risk 0.00cvss epss 0.03

    Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.

  • CVE-2004-1616Oct 18, 2004
    risk 0.00cvss epss 0.02

    Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.

  • CVE-2004-1617Oct 18, 2004
    risk 0.00cvss epss 0.04

    Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not…

  • CVE-2004-1621Oct 18, 2004
    risk 0.03cvss epss 0.03

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1)…

  • CVE-2004-1599Oct 16, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.

  • CVE-2004-1600Oct 16, 2004
    risk 0.00cvss epss 0.02

    index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.

  • CVE-2004-1601Oct 16, 2004
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.

  • CVE-2004-1638Oct 16, 2004
    risk 0.08cvss epss 0.63

    Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.

  • CVE-2004-1602Oct 15, 2004
    risk 0.05cvss epss 0.31

    ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.

  • CVE-2004-1605Oct 14, 2004
    risk 0.00cvss epss 0.02

    SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.

  • CVE-2004-1700Oct 14, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.

  • CVE-2004-1594Oct 13, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.

  • CVE-2004-1595Oct 13, 2004
    risk 0.08cvss epss 0.59

    Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.

  • CVE-2004-1596Oct 13, 2004
    risk 0.03cvss epss 0.03

    The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.

  • CVE-2004-1597Oct 13, 2004
    risk 0.00cvss epss 0.02

    RIM Blackberry 7230 running RIM Blackberry OS 3.7 SP1 allows remote attackers to cause a denial of service (device reboot and possibly data corruption) via a calendar message with a long Location field, which triggers a watchdog while the message is being stored.

  • CVE-2004-1598Oct 12, 2004
    risk 0.00cvss epss 0.03

    Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.

  • CVE-2004-1671Oct 12, 2004
    risk 0.00cvss epss 0.02

    Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.