VYPR

CVEs

378,345 total · page 7397 of 7,567

  • CVE-2004-0715Jul 27, 2004
    risk 0.00cvss epss 0.02

    The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which…

  • CVE-2004-0717Jul 27, 2004
    risk 0.00cvss epss 0.02

    Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

  • CVE-2004-0718Jul 27, 2004
    risk 0.00cvss epss 0.02

    The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame…

  • CVE-2004-0719Jul 27, 2004
    risk 0.00cvss epss 0.05

    Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the…

  • CVE-2004-0720Jul 27, 2004
    risk 0.00cvss epss 0.01

    Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

  • CVE-2004-0721Jul 27, 2004
    risk 0.00cvss epss 0.02

    Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

  • CVE-2004-0723Jul 27, 2004
    risk 0.01cvss epss 0.13

    Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java."

  • CVE-2004-0724Jul 27, 2004
    risk 0.00cvss epss 0.02

    The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.

  • CVE-2004-0725Jul 27, 2004
    risk 0.00cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via the file parameter.

  • CVE-2004-0726Jul 27, 2004
    risk 0.01cvss epss 0.11

    The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.

  • CVE-2004-0727Jul 27, 2004
    risk 0.06cvss epss 0.40

    Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the…

  • CVE-2004-0728Jul 27, 2004
    risk 0.05cvss epss 0.25

    The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.

  • CVE-2004-0729Jul 27, 2004
    risk 0.00cvss epss 0.01

    PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.

  • CVE-2004-0730Jul 27, 2004
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parameter in lang_faq.php as accessible from faq.php, or (3) the faq[0][0] parameter…

  • CVE-2004-0731Jul 27, 2004
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.

  • CVE-2004-0732Jul 27, 2004
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.

  • CVE-2004-0733Jul 27, 2004
    risk 0.03cvss epss 0.05

    Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.

  • CVE-2004-0734Jul 27, 2004
    risk 0.03cvss epss 0.04

    Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

  • CVE-2004-0735Jul 27, 2004
    risk 0.08cvss epss 0.62

    Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo…

  • CVE-2004-0736Jul 27, 2004
    risk 0.00cvss epss 0.01

    The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.

  • CVE-2004-0737Jul 27, 2004
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3…

  • CVE-2004-0738Jul 27, 2004
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.

  • CVE-2004-0739Jul 27, 2004
    risk 0.00cvss epss 0.02

    Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.

  • CVE-2004-0740Jul 27, 2004
    risk 0.03cvss epss 0.03

    The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.

  • CVE-2004-0741Jul 27, 2004
    risk 0.00cvss epss 0.01

    LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.

  • CVE-2004-0742Jul 27, 2004
    risk 0.00cvss epss 0.05

    Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.

  • CVE-2004-2061CriJul 27, 2004
    risk 0.67cvss 9.8epss 0.06

    RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

  • CVE-2004-2051Jul 24, 2004
    risk 0.00cvss epss 0.01

    The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.

  • CVE-2004-2053Jul 24, 2004
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

  • CVE-2004-2047Jul 23, 2004
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.

  • CVE-2004-1749Jul 22, 2004
    risk 0.00cvss epss 0.02

    Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.

  • CVE-2004-2055Jul 19, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

  • CVE-2004-0397Jul 7, 2004
    risk 0.09cvss epss 0.75

    Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.

  • CVE-2004-0398Jul 7, 2004
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.

  • CVE-2004-0399Jul 7, 2004
    risk 0.05cvss epss 0.21

    Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

  • CVE-2004-0400Jul 7, 2004
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.

  • CVE-2004-0401Jul 7, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

  • CVE-2004-0402Jul 7, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.

  • CVE-2004-0404Jul 7, 2004
    risk 0.00cvss epss 0.00

    logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.

  • CVE-2004-0411Jul 7, 2004
    risk 0.01cvss epss 0.08

    The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs,…

  • CVE-2004-0420Jul 7, 2004
    risk 0.04cvss epss 0.46

    The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet…

  • CVE-2004-0422Jul 7, 2004
    risk 0.00cvss epss 0.00

    flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.

  • CVE-2004-0423Jul 7, 2004
    risk 0.00cvss epss 0.00

    The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.

  • CVE-2004-0424Jul 7, 2004
    risk 0.03cvss epss 0.01

    Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

  • CVE-2004-0426Jul 7, 2004
    risk 0.00cvss epss 0.03

    rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.

  • CVE-2004-0427Jul 7, 2004
    risk 0.00cvss epss 0.00

    The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of…

  • CVE-2004-0430Jul 7, 2004
    risk 0.06cvss epss 0.41

    Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string…

  • CVE-2004-0431Jul 7, 2004
    risk 0.00cvss epss 0.03

    Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.

  • CVE-2004-0434CriJul 7, 2004
    risk 0.64cvss 9.8epss 0.07

    k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.

  • CVE-2004-0437Jul 7, 2004
    risk 0.04cvss epss 0.08

    Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.