VYPR

CVEs

378,355 total · page 7392 of 7,568

  • CVE-2004-1642Aug 29, 2004
    risk 0.03cvss epss 0.03

    WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.

  • CVE-2004-1643Aug 29, 2004
    risk 0.04cvss epss 0.07

    WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.

  • CVE-2004-0820Aug 28, 2004
    risk 0.03cvss epss 0.03

    Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.

  • CVE-2004-1640Aug 28, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.

  • CVE-2004-1681Aug 26, 2004
    risk 0.03cvss epss 0.01

    Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.

  • CVE-2004-1751Aug 26, 2004
    risk 0.03cvss epss 0.03

    Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket error that is treated as a critical error.

  • CVE-2004-0819Aug 25, 2004
    risk 0.00cvss epss 0.01

    The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.

  • CVE-2004-1662Aug 25, 2004
    risk 0.00cvss epss 0.02

    YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.

  • CVE-2004-0800Aug 24, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.

  • CVE-2004-1742Aug 24, 2004
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.

  • CVE-2004-1743Aug 24, 2004
    risk 0.00cvss epss 0.02

    Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.

  • CVE-2004-1744Aug 24, 2004
    risk 0.03cvss epss 0.04

    Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.

  • CVE-2004-1745Aug 24, 2004
    risk 0.03cvss epss 0.06

    Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

  • CVE-2004-1752Aug 24, 2004
    risk 0.04cvss epss 0.07

    Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.

  • CVE-2004-1739Aug 23, 2004
    risk 0.03cvss epss 0.03

    Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.

  • CVE-2004-1740Aug 23, 2004
    risk 0.00cvss epss 0.02

    Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.

  • CVE-2004-1741Aug 23, 2004
    risk 0.04cvss epss 0.07

    Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.

  • CVE-2004-1735Aug 21, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.

  • CVE-2004-1726Aug 20, 2004
    risk 0.00cvss epss 0.04

    Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.

  • CVE-2004-1727Aug 20, 2004
    risk 0.03cvss epss 0.03

    BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.

  • CVE-2004-1728Aug 20, 2004
    risk 0.03cvss epss 0.06

    Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.

  • CVE-2004-1729Aug 20, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

  • CVE-2004-1731Aug 20, 2004
    risk 0.03cvss epss 0.03

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.

  • CVE-2004-1732Aug 20, 2004
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.

  • CVE-2004-1733Aug 20, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.

  • CVE-2003-0193Aug 18, 2004
    risk 0.00cvss epss 0.00

    msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").

  • CVE-2003-1042Aug 18, 2004
    risk 0.00cvss epss 0.03

    SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

  • CVE-2003-1043Aug 18, 2004
    risk 0.00cvss epss 0.03

    SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.

  • CVE-2003-1044Aug 18, 2004
    risk 0.00cvss epss 0.01

    editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the…

  • CVE-2003-1045Aug 18, 2004
    risk 0.00cvss epss 0.01

    votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.

  • CVE-2003-1046Aug 18, 2004
    risk 0.00cvss epss 0.01

    describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.

  • CVE-2004-0134Aug 18, 2004
    risk 0.00cvss epss 0.00

    cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.

  • CVE-2004-0175Aug 18, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

  • CVE-2004-0226Aug 18, 2004
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  • CVE-2004-0228Aug 18, 2004
    risk 0.03cvss epss 0.01

    Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.

  • CVE-2004-0229Aug 18, 2004
    risk 0.00cvss epss 0.00

    The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.

  • CVE-2004-0230Aug 18, 2004
    risk 0.09cvss epss 0.80

    TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections,…

  • CVE-2004-0231Aug 18, 2004
    risk 0.00cvss epss 0.00

    Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

  • CVE-2004-0232Aug 18, 2004
    risk 0.00cvss epss 0.03

    Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

  • CVE-2004-0233Aug 18, 2004
    risk 0.03cvss epss 0.01

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

  • CVE-2004-0234Aug 18, 2004
    risk 0.01cvss epss 0.10

    Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the…

  • CVE-2004-0235Aug 18, 2004
    risk 0.00cvss epss 0.04

    Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

  • CVE-2004-0375Aug 18, 2004
    risk 0.04cvss epss 0.09

    SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or…

  • CVE-2004-0394Aug 18, 2004
    risk 0.00cvss epss 0.00

    A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.

  • CVE-2004-0412Aug 18, 2004
    risk 0.00cvss epss 0.03

    Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

  • CVE-2004-0419Aug 18, 2004
    risk 0.00cvss epss 0.02

    XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

  • CVE-2004-0421Aug 18, 2004
    risk 0.00cvss epss 0.04

    The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.

  • CVE-2004-0425Aug 18, 2004
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.

  • CVE-2004-0432Aug 18, 2004
    risk 0.01cvss epss 0.09

    ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.

  • CVE-2004-0433Aug 18, 2004
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute…