VYPR

CVEs

378,356 total · page 7390 of 7,568

  • CVE-2002-1583Sep 28, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.

  • CVE-2003-0105Sep 28, 2004
    risk 0.00cvss epss 0.03

    ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.

  • CVE-2003-0928Sep 28, 2004
    risk 0.00cvss epss 0.01

    Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.

  • CVE-2003-0929Sep 28, 2004
    risk 0.00cvss epss 0.02

    Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.

  • CVE-2003-0930Sep 28, 2004
    risk 0.00cvss epss 0.01

    Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.

  • CVE-2003-0931Sep 28, 2004
    risk 0.00cvss epss 0.02

    Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.

  • CVE-2003-1049Sep 28, 2004
    risk 0.00cvss epss 0.00

    IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.

  • CVE-2003-1050Sep 28, 2004
    risk 0.03cvss epss 0.01

    Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

  • CVE-2003-1051Sep 28, 2004
    risk 0.03cvss epss 0.01

    Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

  • CVE-2003-1052Sep 28, 2004
    risk 0.03cvss epss 0.01

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

  • CVE-2004-0163Sep 28, 2004
    risk 0.00cvss epss 0.02

    Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.

  • CVE-2004-0200Sep 28, 2004
    risk 0.07cvss epss 0.49

    Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length…

  • CVE-2004-0408Sep 28, 2004
    risk 0.00cvss epss 0.03

    Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.

  • CVE-2004-0457Sep 28, 2004
    risk 0.00cvss epss 0.01

    The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2004-0458HigSep 28, 2004
    risk 0.49cvss 7.5epss 0.03

    mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.

  • CVE-2004-0500Sep 28, 2004
    risk 0.00cvss epss 0.05

    Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.

  • CVE-2004-0558Sep 28, 2004
    risk 0.05cvss epss 0.27

    The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.

  • CVE-2004-0573Sep 28, 2004
    risk 0.03cvss epss 0.42

    Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.

  • CVE-2004-0593Sep 28, 2004
    risk 0.00cvss epss 0.02

    Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.

  • CVE-2004-0629Sep 28, 2004
    risk 0.01cvss epss 0.07

    Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.

  • CVE-2004-0642Sep 28, 2004
    risk 0.01cvss epss 0.08

    Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

  • CVE-2004-0643Sep 28, 2004
    risk 0.01cvss epss 0.09

    Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.

  • CVE-2004-0644Sep 28, 2004
    risk 0.00cvss epss 0.06

    The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.

  • CVE-2004-0689HigSep 28, 2004
    risk 0.46cvss 7.1epss 0.00

    KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.

  • CVE-2004-0690Sep 28, 2004
    risk 0.00cvss epss 0.01

    The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.

  • CVE-2004-0691Sep 28, 2004
    risk 0.04cvss epss 0.15

    Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.

  • CVE-2004-0692Sep 28, 2004
    risk 0.00cvss epss 0.03

    The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.

  • CVE-2004-0693Sep 28, 2004
    risk 0.00cvss epss 0.03

    The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.

  • CVE-2004-0699Sep 28, 2004
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.

  • CVE-2004-0745Sep 28, 2004
    risk 0.00cvss epss 0.03

    LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.

  • CVE-2004-1698Sep 24, 2004
    risk 0.03cvss epss 0.03

    The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.

  • CVE-2004-1378Sep 21, 2004
    risk 0.00cvss epss 0.02

    The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML…

  • CVE-2004-1694Sep 21, 2004
    risk 0.00cvss epss 0.02

    Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.

  • CVE-2004-1696Sep 21, 2004
    risk 0.04cvss epss 0.08

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.

  • CVE-2004-1697Sep 21, 2004
    risk 0.00cvss epss 0.02

    The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.

  • CVE-2004-1699Sep 21, 2004
    risk 0.04cvss epss 0.08

    SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

  • CVE-2004-1695Sep 20, 2004
    risk 0.04cvss epss 0.10

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).

  • CVE-2004-1690Sep 18, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.

  • CVE-2004-1691Sep 18, 2004
    risk 0.03cvss epss 0.04

    The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.

  • CVE-2004-1692Sep 18, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.

  • CVE-2004-1693Sep 18, 2004
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-0534Sep 17, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

  • CVE-2004-0801Sep 16, 2004
    risk 0.00cvss epss 0.04

    Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.

  • CVE-2004-0809Sep 16, 2004
    risk 0.01cvss epss 0.17

    The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

  • CVE-2004-0827Sep 16, 2004
    risk 0.00cvss epss 0.06

    Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.

  • CVE-2004-0866Sep 16, 2004
    risk 0.01cvss epss 0.10

    Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

  • CVE-2004-0869Sep 16, 2004
    risk 0.01cvss epss 0.15

    Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security…

  • CVE-2004-0870Sep 16, 2004
    risk 0.00cvss epss 0.01

    KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary…

  • CVE-2004-0871Sep 16, 2004
    risk 0.00cvss epss 0.01

    Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie…

  • CVE-2004-0872Sep 16, 2004
    risk 0.00cvss epss 0.03

    Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie…