VYPR

CVEs

378,267 total · page 7401 of 7,566

  • CVE-2004-1932Apr 12, 2004
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

  • CVE-2004-1933Apr 12, 2004
    risk 0.00cvss epss 0.00

    Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.

  • CVE-2004-1922Apr 11, 2004
    risk 0.01cvss epss 0.07

    Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.

  • CVE-2004-1923Apr 11, 2004
    risk 0.03cvss epss 0.03

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an…

  • CVE-2004-1924Apr 11, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php,…

  • CVE-2004-1926Apr 11, 2004
    risk 0.04cvss epss 0.07

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a…

  • CVE-2004-1927Apr 11, 2004
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.

  • CVE-2004-1920Apr 10, 2004
    risk 0.00cvss epss 0.02

    X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

  • CVE-2004-1921Apr 10, 2004
    risk 0.00cvss epss 0.02

    X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.

  • CVE-2004-1918Apr 9, 2004
    risk 0.00cvss epss 0.02

    RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.

  • CVE-2004-1919Apr 9, 2004
    risk 0.03cvss epss 0.03

    The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.

  • CVE-2004-1915Apr 8, 2004
    risk 0.04cvss epss 0.09

    Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.

  • CVE-2004-1916Apr 8, 2004
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.

  • CVE-2004-1917Apr 8, 2004
    risk 0.00cvss epss 0.04

    Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.

  • CVE-2004-1357Apr 7, 2004
    risk 0.00cvss epss 0.03

    The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.

  • CVE-2004-1986Apr 4, 2004
    risk 0.04cvss epss 0.11

    Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

  • CVE-2004-1890Apr 2, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.

  • CVE-2004-1875Mar 30, 2004
    risk 0.03cvss epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to…

  • CVE-2004-1876Mar 30, 2004
    risk 0.00cvss epss 0.01

    The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

  • CVE-2004-1877Mar 30, 2004
    risk 0.00cvss epss 0.03

    The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and…

  • CVE-2004-1878Mar 30, 2004
    risk 0.03cvss epss 0.03

    LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).

  • CVE-2003-0170Mar 29, 2004
    risk 0.00cvss epss 0.03

    Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

  • CVE-2003-0444Mar 29, 2004
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.

  • CVE-2003-0601Mar 29, 2004
    risk 0.00cvss epss 0.01

    Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.

  • CVE-2003-0607Mar 29, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.

  • CVE-2003-0612Mar 29, 2004
    risk 0.00cvss epss 0.00

    Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.

  • CVE-2003-0796Mar 29, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.

  • CVE-2003-0797Mar 29, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.

  • CVE-2003-0828Mar 29, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.

  • CVE-2003-0993Mar 29, 2004
    risk 0.01cvss epss 0.11

    mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

  • CVE-2003-1006Mar 29, 2004
    risk 0.03cvss epss 0.01

    Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.

  • CVE-2003-1007Mar 29, 2004
    risk 0.00cvss epss 0.01

    AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.

  • CVE-2003-1008Mar 29, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.

  • CVE-2003-1009Mar 29, 2004
    risk 0.00cvss epss 0.05

    Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain…

  • CVE-2003-1010Mar 29, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.

  • CVE-2003-1011Mar 29, 2004
    risk 0.00cvss epss 0.00

    Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.

  • CVE-2003-1018Mar 29, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

  • CVE-2004-0113Mar 29, 2004
    risk 0.01cvss epss 0.11

    Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.

  • CVE-2004-0126Mar 29, 2004
    risk 0.00cvss epss 0.00

    The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.

  • CVE-2004-0158Mar 29, 2004
    risk 0.03cvss epss 0.01

    Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.

  • CVE-2004-0160Mar 29, 2004
    risk 0.00cvss epss 0.00

    Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

  • CVE-2004-0194Mar 29, 2004
    risk 0.04cvss epss 0.11

    Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.

  • CVE-2004-1870Mar 29, 2004
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5)…

  • CVE-2004-1871Mar 29, 2004
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to…

  • CVE-2004-1872Mar 29, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.

  • CVE-2004-1874Mar 29, 2004
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.

  • CVE-2004-1862Mar 26, 2004
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest…

  • CVE-2004-1864Mar 26, 2004
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.

  • CVE-2004-1865MedMar 26, 2004
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other…

  • CVE-2004-1866Mar 26, 2004
    risk 0.03cvss epss 0.03

    nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.