VYPR

CVEs

378,283 total · page 7405 of 7,566

  • CVE-2004-0058Feb 17, 2004
    risk 0.00cvss epss 0.00

    Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.

  • CVE-2004-0059Feb 17, 2004
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.

  • CVE-2004-0060Feb 17, 2004
    risk 0.00cvss epss 0.01

    WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.

  • CVE-2004-0061Feb 17, 2004
    risk 0.00cvss epss 0.01

    WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.

  • CVE-2004-0062Feb 17, 2004
    risk 0.00cvss epss 0.01

    Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.

  • CVE-2004-0063Feb 17, 2004
    risk 0.00cvss epss 0.01

    The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.

  • CVE-2004-0064Feb 17, 2004
    risk 0.03cvss epss 0.01

    The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.

  • CVE-2004-0065Feb 17, 2004
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.

  • CVE-2004-0066Feb 17, 2004
    risk 0.00cvss epss 0.01

    phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.

  • CVE-2004-0067Feb 17, 2004
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8)…

  • CVE-2004-0068Feb 17, 2004
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-0069Feb 17, 2004
    risk 0.04cvss epss 0.10

    Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

  • CVE-2004-0070Feb 17, 2004
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

  • CVE-2004-0071Feb 17, 2004
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.

  • CVE-2004-0072Feb 17, 2004
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.

  • CVE-2004-0073Feb 17, 2004
    risk 0.04cvss epss 0.09

    PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious…

  • CVE-2004-0074Feb 17, 2004
    risk 0.03cvss epss 0.01

    Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.

  • CVE-2004-0091Feb 17, 2004
    risk 0.00cvss epss 0.01

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has…

  • CVE-2004-0095Feb 17, 2004
    risk 0.06cvss epss 0.37

    McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.

  • CVE-2004-1180Feb 16, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

  • CVE-2004-2082Feb 13, 2004
    risk 0.04cvss epss 0.07

    The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.

  • CVE-2004-2088Feb 12, 2004
    risk 0.01cvss epss 0.07

    Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.

  • CVE-2003-1214Feb 11, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.

  • CVE-2004-2083Feb 11, 2004
    risk 0.00cvss epss 0.03

    Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."

  • CVE-2004-2091Feb 10, 2004
    risk 0.00cvss epss 0.03

    Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.

  • CVE-2004-2078Feb 9, 2004
    risk 0.03cvss epss 0.05

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.

  • CVE-2004-2079Feb 9, 2004
    risk 0.00cvss epss 0.02

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.

  • CVE-2004-2080Feb 9, 2004
    risk 0.00cvss epss 0.02

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.

  • CVE-2004-2092Feb 9, 2004
    risk 0.00cvss epss 0.00

    eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.

  • CVE-2004-2093Feb 9, 2004
    risk 0.03cvss epss 0.01

    Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not…

  • CVE-2004-1244Feb 8, 2004
    risk 0.03cvss epss 0.33

    Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

  • CVE-2004-2077Feb 8, 2004
    risk 0.03cvss epss 0.04

    Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.

  • CVE-2004-2087Feb 8, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.

  • CVE-2004-2084Feb 7, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.

  • CVE-2004-2090Feb 7, 2004
    risk 0.04cvss epss 0.16

    Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

  • CVE-2004-2073Feb 6, 2004
    risk 0.03cvss epss 0.03

    Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.

  • CVE-2004-2086Feb 6, 2004
    risk 0.09cvss epss 0.75

    Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.

  • CVE-2004-2089Feb 6, 2004
    risk 0.00cvss epss 0.02

    Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.

  • CVE-2004-2085Feb 4, 2004
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to…

  • CVE-2002-0034Feb 3, 2004
    risk 0.00cvss epss 0.02

    The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.

  • CVE-2002-0712Feb 3, 2004
    risk 0.00cvss epss 0.05

    Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

  • CVE-2003-0119Feb 3, 2004
    risk 0.00cvss epss 0.02

    The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.

  • CVE-2003-0175Feb 3, 2004
    risk 0.00cvss epss 0.00

    SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.

  • CVE-2003-0368Feb 3, 2004
    risk 0.00cvss epss 0.02

    Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.

  • CVE-2003-0814Feb 3, 2004
    risk 0.02cvss epss 0.28

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross…

  • CVE-2003-0815Feb 3, 2004
    risk 0.01cvss epss 0.19

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the…

  • CVE-2003-0816Feb 3, 2004
    risk 0.07cvss epss 0.48

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript,…

  • CVE-2003-0817Feb 3, 2004
    risk 0.01cvss epss 0.18

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.

  • CVE-2003-0823Feb 3, 2004
    risk 0.02cvss epss 0.26

    Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.

  • CVE-2003-0902Feb 3, 2004
    risk 0.00cvss epss 0.03

    Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.