| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0490 | 0.03 | — | 0.04 | Aug 18, 2004 | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to… | |||
| CVE-2004-0501 | 0.04 | — | 0.19 | Aug 18, 2004 | Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote… | |||
| CVE-2004-0502 | 0.05 | — | 0.20 | Aug 18, 2004 | Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as… | |||
| CVE-2004-0503 | 0.01 | — | 0.11 | Aug 18, 2004 | Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting… | |||
| CVE-2004-0504 | 0.00 | — | 0.03 | Aug 18, 2004 | Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients. | |||
| CVE-2004-0505 | 0.00 | — | 0.03 | Aug 18, 2004 | The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors. | |||
| CVE-2004-0506 | 0.00 | — | 0.04 | Aug 18, 2004 | The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference. | |||
| CVE-2004-0507 | 0.01 | — | 0.08 | Aug 18, 2004 | Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |||
| CVE-2004-0513 | 0.00 | — | 0.02 | Aug 18, 2004 | Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls." | |||
| CVE-2004-0514 | 0.00 | — | 0.00 | Aug 18, 2004 | Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups." | |||
| CVE-2004-0515 | 0.00 | — | 0.00 | Aug 18, 2004 | Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files." | |||
| CVE-2004-0516 | 0.00 | — | 0.00 | Aug 18, 2004 | Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517. | |||
| CVE-2004-0517 | 0.00 | — | 0.00 | Aug 18, 2004 | Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516. | |||
| CVE-2004-0518 | 0.00 | — | 0.01 | Aug 18, 2004 | Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors. | |||
| CVE-2004-0519 | 0.05 | — | 0.23 | Aug 18, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php. | |||
| CVE-2004-0520 | 0.04 | — | 0.07 | Aug 18, 2004 | Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php. | |||
| CVE-2004-0521 | 0.00 | — | 0.03 | Aug 18, 2004 | SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php. | |||
| CVE-2004-0523 | 0.01 | — | 0.12 | Aug 18, 2004 | Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root. | |||
| CVE-2004-0630 | 0.01 | — | 0.08 | Aug 18, 2004 | The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is… | |||
| CVE-2004-0631 | 0.01 | — | 0.10 | Aug 18, 2004 | Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the… | |||
| CVE-2004-0722 | 0.04 | — | 0.13 | Aug 18, 2004 | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code. | |||
| CVE-2004-0757 | 0.00 | — | 0.05 | Aug 18, 2004 | Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code. | |||
| CVE-2004-0758 | 0.00 | — | 0.03 | Aug 18, 2004 | Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid. | |||
| CVE-2004-0759 | 0.00 | — | 0.02 | Aug 18, 2004 | Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an tag. | |||
| CVE-2004-0760 | 0.04 | — | 0.09 | Aug 18, 2004 | Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI. | |||
| CVE-2004-0761 | 0.00 | — | 0.02 | Aug 18, 2004 | Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted. | |||
| CVE-2004-0762 | 0.00 | — | 0.02 | Aug 18, 2004 | Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box. | |||
| CVE-2004-0763 | 0.03 | — | 0.06 | Aug 18, 2004 | Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method. | |||
| CVE-2004-0764 | 0.00 | — | 0.03 | Aug 18, 2004 | Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files. | |||
| CVE-2004-0765 | 0.00 | — | 0.01 | Aug 18, 2004 | The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof… | |||
| CVE-2004-0766 | 0.00 | — | 0.01 | Aug 18, 2004 | NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions. | |||
| CVE-2004-0767 | 0.00 | — | 0.01 | Aug 18, 2004 | NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions. | |||
| CVE-2004-0769 | 0.01 | — | 0.07 | Aug 18, 2004 | Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than… | |||
| CVE-2004-0779 | 0.00 | — | 0.02 | Aug 18, 2004 | The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to… | |||
| CVE-2004-0839 | 0.03 | — | 0.34 | Aug 18, 2004 | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the… | |||
| CVE-2004-1724 | 0.04 | — | 0.07 | Aug 18, 2004 | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain… | |||
| CVE-2004-1718 | 0.00 | — | 0.00 | Aug 17, 2004 | The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument. | |||
| CVE-2004-1719 | 0.03 | — | 0.05 | Aug 17, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or… | |||
| CVE-2004-1720 | 0.04 | — | 0.08 | Aug 17, 2004 | The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the… | |||
| CVE-2004-1721 | 0.00 | — | 0.02 | Aug 17, 2004 | The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000. | |||
| CVE-2004-1722 | 0.03 | — | 0.03 | Aug 17, 2004 | SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter. | |||
| CVE-2004-1716 | 0.00 | — | 0.02 | Aug 16, 2004 | Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile. | |||
| CVE-2004-1717 | 0.03 | — | 0.05 | Aug 16, 2004 | Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value. | |||
| CVE-2004-1737 | 0.03 | — | 0.03 | Aug 16, 2004 | SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters. | |||
| CVE-2004-1682 | 0.00 | — | 0.02 | Aug 15, 2004 | Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command. | |||
| CVE-2004-1714 | Hig | 0.49 | 7.1 | 0.01 | Aug 11, 2004 | BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying… | ||
| CVE-2004-1715 | 0.00 | — | 0.02 | Aug 11, 2004 | Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL. | |||
| CVE-2004-1347 | 0.00 | — | 0.04 | Aug 10, 2004 | X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request. | |||
| CVE-2004-1713 | 0.00 | — | 0.00 | Aug 10, 2004 | Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files. | |||
| CVE-2004-1701 | 0.05 | — | 0.20 | Aug 9, 2004 | Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication. |
- CVE-2004-0490Aug 18, 2004risk 0.03cvss —epss 0.04
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to…
- CVE-2004-0501Aug 18, 2004risk 0.04cvss —epss 0.19
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote…
- CVE-2004-0502Aug 18, 2004risk 0.05cvss —epss 0.20
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as…
- CVE-2004-0503Aug 18, 2004risk 0.01cvss —epss 0.11
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting…
- CVE-2004-0504Aug 18, 2004risk 0.00cvss —epss 0.03
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
- CVE-2004-0505Aug 18, 2004risk 0.00cvss —epss 0.03
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
- CVE-2004-0506Aug 18, 2004risk 0.00cvss —epss 0.04
The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.
- CVE-2004-0507Aug 18, 2004risk 0.01cvss —epss 0.08
Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
- CVE-2004-0513Aug 18, 2004risk 0.00cvss —epss 0.02
Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."
- CVE-2004-0514Aug 18, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
- CVE-2004-0515Aug 18, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."
- CVE-2004-0516Aug 18, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
- CVE-2004-0517Aug 18, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.
- CVE-2004-0518Aug 18, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.
- CVE-2004-0519Aug 18, 2004risk 0.05cvss —epss 0.23
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
- CVE-2004-0520Aug 18, 2004risk 0.04cvss —epss 0.07
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
- CVE-2004-0521Aug 18, 2004risk 0.00cvss —epss 0.03
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
- CVE-2004-0523Aug 18, 2004risk 0.01cvss —epss 0.12
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
- CVE-2004-0630Aug 18, 2004risk 0.01cvss —epss 0.08
The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is…
- CVE-2004-0631Aug 18, 2004risk 0.01cvss —epss 0.10
Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via a long filename for the PDF file that is provided to the…
- CVE-2004-0722Aug 18, 2004risk 0.04cvss —epss 0.13
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
- CVE-2004-0757Aug 18, 2004risk 0.00cvss —epss 0.05
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
- CVE-2004-0758Aug 18, 2004risk 0.00cvss —epss 0.03
Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.
- CVE-2004-0759Aug 18, 2004risk 0.00cvss —epss 0.02
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an tag.
- CVE-2004-0760Aug 18, 2004risk 0.04cvss —epss 0.09
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.
- CVE-2004-0761Aug 18, 2004risk 0.00cvss —epss 0.02
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
- CVE-2004-0762Aug 18, 2004risk 0.00cvss —epss 0.02
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
- CVE-2004-0763Aug 18, 2004risk 0.03cvss —epss 0.06
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.
- CVE-2004-0764Aug 18, 2004risk 0.00cvss —epss 0.03
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
- CVE-2004-0765Aug 18, 2004risk 0.00cvss —epss 0.01
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof…
- CVE-2004-0766Aug 18, 2004risk 0.00cvss —epss 0.01
NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.
- CVE-2004-0767Aug 18, 2004risk 0.00cvss —epss 0.01
NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions.
- CVE-2004-0769Aug 18, 2004risk 0.01cvss —epss 0.07
Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than…
- CVE-2004-0779Aug 18, 2004risk 0.00cvss —epss 0.02
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to…
- CVE-2004-0839Aug 18, 2004risk 0.03cvss —epss 0.34
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the…
- CVE-2004-1724Aug 18, 2004risk 0.04cvss —epss 0.07
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain…
- CVE-2004-1718Aug 17, 2004risk 0.00cvss —epss 0.00
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
- CVE-2004-1719Aug 17, 2004risk 0.03cvss —epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or…
- CVE-2004-1720Aug 17, 2004risk 0.04cvss —epss 0.08
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the…
- CVE-2004-1721Aug 17, 2004risk 0.00cvss —epss 0.02
The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
- CVE-2004-1722Aug 17, 2004risk 0.03cvss —epss 0.03
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.
- CVE-2004-1716Aug 16, 2004risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.
- CVE-2004-1717Aug 16, 2004risk 0.03cvss —epss 0.05
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.
- CVE-2004-1737Aug 16, 2004risk 0.03cvss —epss 0.03
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
- CVE-2004-1682Aug 15, 2004risk 0.00cvss —epss 0.02
Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.
- risk 0.49cvss 7.1epss 0.01
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying…
- CVE-2004-1715Aug 11, 2004risk 0.00cvss —epss 0.02
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
- CVE-2004-1347Aug 10, 2004risk 0.00cvss —epss 0.04
X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.
- CVE-2004-1713Aug 10, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.
- CVE-2004-1701Aug 9, 2004risk 0.05cvss —epss 0.20
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.