| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0058 | 0.00 | — | 0.00 | Feb 17, 2004 | Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file. | |||
| CVE-2004-0059 | 0.00 | — | 0.01 | Feb 17, 2004 | Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header. | |||
| CVE-2004-0060 | 0.00 | — | 0.01 | Feb 17, 2004 | WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request. | |||
| CVE-2004-0061 | 0.00 | — | 0.01 | Feb 17, 2004 | WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character. | |||
| CVE-2004-0062 | 0.00 | — | 0.01 | Feb 17, 2004 | Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity. | |||
| CVE-2004-0063 | 0.00 | — | 0.01 | Feb 17, 2004 | The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number. | |||
| CVE-2004-0064 | 0.03 | — | 0.01 | Feb 17, 2004 | The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory. | |||
| CVE-2004-0065 | 0.00 | — | 0.02 | Feb 17, 2004 | Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php. | |||
| CVE-2004-0066 | 0.00 | — | 0.01 | Feb 17, 2004 | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php. | |||
| CVE-2004-0067 | 0.03 | — | 0.03 | Feb 17, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8)… | |||
| CVE-2004-0068 | 0.00 | — | 0.01 | Feb 17, 2004 | PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code. | |||
| CVE-2004-0069 | 0.04 | — | 0.10 | Feb 17, 2004 | Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function. | |||
| CVE-2004-0070 | 0.03 | — | 0.03 | Feb 17, 2004 | PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code. | |||
| CVE-2004-0071 | — | 0.04 | — | 0.07 | Feb 17, 2004 | Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php. | ||
| CVE-2004-0072 | 0.03 | — | 0.04 | Feb 17, 2004 | Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request. | |||
| CVE-2004-0073 | 0.04 | — | 0.09 | Feb 17, 2004 | PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious… | |||
| CVE-2004-0074 | 0.03 | — | 0.01 | Feb 17, 2004 | Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949. | |||
| CVE-2004-0091 | 0.00 | — | 0.01 | Feb 17, 2004 | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has… | |||
| CVE-2004-0095 | 0.06 | — | 0.37 | Feb 17, 2004 | McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow. | |||
| CVE-2004-1180 | 0.00 | — | 0.02 | Feb 16, 2004 | Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash). | |||
| CVE-2004-2082 | 0.04 | — | 0.07 | Feb 13, 2004 | The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters. | |||
| CVE-2004-2088 | 0.01 | — | 0.07 | Feb 12, 2004 | Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message. | |||
| CVE-2003-1214 | 0.00 | — | 0.02 | Feb 11, 2004 | Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions. | |||
| CVE-2004-2083 | 0.00 | — | 0.03 | Feb 11, 2004 | Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing." | |||
| CVE-2004-2091 | 0.00 | — | 0.03 | Feb 10, 2004 | Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | |||
| CVE-2004-2078 | 0.03 | — | 0.05 | Feb 9, 2004 | Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow. | |||
| CVE-2004-2079 | 0.00 | — | 0.02 | Feb 9, 2004 | Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user. | |||
| CVE-2004-2080 | 0.00 | — | 0.02 | Feb 9, 2004 | Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID. | |||
| CVE-2004-2092 | 0.00 | — | 0.00 | Feb 9, 2004 | eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information. | |||
| CVE-2004-2093 | 0.03 | — | 0.01 | Feb 9, 2004 | Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not… | |||
| CVE-2004-1244 | 0.03 | — | 0.33 | Feb 8, 2004 | Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability." | |||
| CVE-2004-2077 | 0.03 | — | 0.04 | Feb 8, 2004 | Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields. | |||
| CVE-2004-2087 | 0.00 | — | 0.02 | Feb 8, 2004 | Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user. | |||
| CVE-2004-2084 | 0.00 | — | 0.01 | Feb 7, 2004 | Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter. | |||
| CVE-2004-2090 | 0.04 | — | 0.16 | Feb 7, 2004 | Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist. | |||
| CVE-2004-2073 | 0.03 | — | 0.03 | Feb 6, 2004 | Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command. | |||
| CVE-2004-2086 | 0.09 | — | 0.75 | Feb 6, 2004 | Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter. | |||
| CVE-2004-2089 | 0.00 | — | 0.02 | Feb 6, 2004 | Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command. | |||
| CVE-2004-2085 | 0.00 | — | 0.02 | Feb 4, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to… | |||
| CVE-2002-0034 | 0.00 | — | 0.02 | Feb 3, 2004 | The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected. | |||
| CVE-2002-0712 | 0.00 | — | 0.05 | Feb 3, 2004 | Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations. | |||
| CVE-2003-0119 | 0.00 | — | 0.02 | Feb 3, 2004 | The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities. | |||
| CVE-2003-0175 | 0.00 | — | 0.00 | Feb 3, 2004 | SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl. | |||
| CVE-2003-0368 | 0.00 | — | 0.02 | Feb 3, 2004 | Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option. | |||
| CVE-2003-0814 | 0.02 | — | 0.28 | Feb 3, 2004 | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross… | |||
| CVE-2003-0815 | 0.01 | — | 0.19 | Feb 3, 2004 | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the… | |||
| CVE-2003-0816 | 0.07 | — | 0.48 | Feb 3, 2004 | Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript,… | |||
| CVE-2003-0817 | 0.01 | — | 0.18 | Feb 3, 2004 | Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object. | |||
| CVE-2003-0823 | 0.02 | — | 0.26 | Feb 3, 2004 | Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027. | |||
| CVE-2003-0902 | 0.00 | — | 0.03 | Feb 3, 2004 | Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands. |
- CVE-2004-0058Feb 17, 2004risk 0.00cvss —epss 0.00
Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.
- CVE-2004-0059Feb 17, 2004risk 0.00cvss —epss 0.01
Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.
- CVE-2004-0060Feb 17, 2004risk 0.00cvss —epss 0.01
WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.
- CVE-2004-0061Feb 17, 2004risk 0.00cvss —epss 0.01
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.
- CVE-2004-0062Feb 17, 2004risk 0.00cvss —epss 0.01
Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.
- CVE-2004-0063Feb 17, 2004risk 0.00cvss —epss 0.01
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.
- CVE-2004-0064Feb 17, 2004risk 0.03cvss —epss 0.01
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.
- CVE-2004-0065Feb 17, 2004risk 0.00cvss —epss 0.02
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.
- CVE-2004-0066Feb 17, 2004risk 0.00cvss —epss 0.01
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.
- CVE-2004-0067Feb 17, 2004risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8)…
- CVE-2004-0068Feb 17, 2004risk 0.00cvss —epss 0.01
PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.
- CVE-2004-0069Feb 17, 2004risk 0.04cvss —epss 0.10
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
- CVE-2004-0070Feb 17, 2004risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.
- CVE-2004-0071Feb 17, 2004risk 0.04cvss —epss 0.07
Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.
- CVE-2004-0072Feb 17, 2004risk 0.03cvss —epss 0.04
Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.
- CVE-2004-0073Feb 17, 2004risk 0.04cvss —epss 0.09
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious…
- CVE-2004-0074Feb 17, 2004risk 0.03cvss —epss 0.01
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.
- CVE-2004-0091Feb 17, 2004risk 0.00cvss —epss 0.01
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has…
- CVE-2004-0095Feb 17, 2004risk 0.06cvss —epss 0.37
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
- CVE-2004-1180Feb 16, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).
- CVE-2004-2082Feb 13, 2004risk 0.04cvss —epss 0.07
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.
- CVE-2004-2088Feb 12, 2004risk 0.01cvss —epss 0.07
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
- CVE-2003-1214Feb 11, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.
- CVE-2004-2083Feb 11, 2004risk 0.00cvss —epss 0.03
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
- CVE-2004-2091Feb 10, 2004risk 0.00cvss —epss 0.03
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
- CVE-2004-2078Feb 9, 2004risk 0.03cvss —epss 0.05
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.
- CVE-2004-2079Feb 9, 2004risk 0.00cvss —epss 0.02
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
- CVE-2004-2080Feb 9, 2004risk 0.00cvss —epss 0.02
Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.
- CVE-2004-2092Feb 9, 2004risk 0.00cvss —epss 0.00
eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.
- CVE-2004-2093Feb 9, 2004risk 0.03cvss —epss 0.01
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not…
- CVE-2004-1244Feb 8, 2004risk 0.03cvss —epss 0.33
Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."
- CVE-2004-2077Feb 8, 2004risk 0.03cvss —epss 0.04
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.
- CVE-2004-2087Feb 8, 2004risk 0.00cvss —epss 0.02
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
- CVE-2004-2084Feb 7, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.
- CVE-2004-2090Feb 7, 2004risk 0.04cvss —epss 0.16
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.
- CVE-2004-2073Feb 6, 2004risk 0.03cvss —epss 0.03
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.
- CVE-2004-2086Feb 6, 2004risk 0.09cvss —epss 0.75
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.
- CVE-2004-2089Feb 6, 2004risk 0.00cvss —epss 0.02
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.
- CVE-2004-2085Feb 4, 2004risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to…
- CVE-2002-0034Feb 3, 2004risk 0.00cvss —epss 0.02
The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
- CVE-2002-0712Feb 3, 2004risk 0.00cvss —epss 0.05
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
- CVE-2003-0119Feb 3, 2004risk 0.00cvss —epss 0.02
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.
- CVE-2003-0175Feb 3, 2004risk 0.00cvss —epss 0.00
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.
- CVE-2003-0368Feb 3, 2004risk 0.00cvss —epss 0.02
Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.
- CVE-2003-0814Feb 3, 2004risk 0.02cvss —epss 0.28
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross…
- CVE-2003-0815Feb 3, 2004risk 0.01cvss —epss 0.19
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the…
- CVE-2003-0816Feb 3, 2004risk 0.07cvss —epss 0.48
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript,…
- CVE-2003-0817Feb 3, 2004risk 0.01cvss —epss 0.18
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.
- CVE-2003-0823Feb 3, 2004risk 0.02cvss —epss 0.26
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.
- CVE-2003-0902Feb 3, 2004risk 0.00cvss —epss 0.03
Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.