Search
Total
25555 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2004-0314 | 1 Freewebs | 1 Webzedit | 2017-07-11 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter. | |||||
| CVE-2004-0313 | 1 Psoproxy | 1 Psoproxy Server | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name. | |||||
| CVE-2004-1217 | 1 Hosting Controller | 1 Hosting Controller | 2017-07-11 | 5.0 MEDIUM | N/A |
| Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp. | |||||
| CVE-2004-0312 | 1 Linksys | 1 Wap55ag | 2017-07-11 | 6.4 MEDIUM | N/A |
| Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2. | |||||
| CVE-2004-0305 | 1 Webcortex | 1 Webstores 2000 | 2017-07-11 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | |||||
| CVE-2004-0304 | 1 Webcortex | 1 Webstores 2000 | 2017-07-11 | 10.0 HIGH | N/A |
| SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | |||||
| CVE-2004-0303 | 1 Fools Workshop | 1 Owls Workshop | 2017-07-11 | 5.0 MEDIUM | N/A |
| OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | |||||
| CVE-2004-0302 | 1 Fools Workshop | 1 Owls Workshop | 2017-07-11 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | |||||
| CVE-2004-0301 | 1 Ecommerce Corporation Online | 1 Store Kit | 2017-07-11 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | |||||
| CVE-2004-0300 | 1 Ecommerce Corporation Online | 1 Store Kit | 2017-07-11 | 10.0 HIGH | N/A |
| SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. | |||||
| CVE-2004-0299 | 1 Smallftpd | 1 Smallftpd | 2017-07-11 | 2.1 LOW | N/A |
| Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters. | |||||
| CVE-2004-0298 | 1 Aclogic | 1 Cesarftp | 2017-07-11 | 5.0 MEDIUM | N/A |
| CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter. | |||||
| CVE-2004-0296 | 1 Transsoft | 1 Broker Ftp Server | 2017-07-11 | 5.0 MEDIUM | N/A |
| TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection. | |||||
| CVE-2004-0295 | 1 Transsoft | 1 Broker Ftp Server | 2017-07-11 | 5.0 MEDIUM | N/A |
| TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection. | |||||
| CVE-2004-0294 | 1 Yabb | 1 Yabb | 2017-07-11 | 5.0 MEDIUM | N/A |
| YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack. | |||||
| CVE-2004-0293 | 1 Shopcartcgi | 1 Shopcartcgi | 2017-07-11 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi. | |||||
| CVE-2004-0292 | 1 Karjasoft | 1 Sami Http Server | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | |||||
| CVE-2004-0291 | 1 Yabb | 1 Yabb | 2017-07-11 | 5.0 MEDIUM | N/A |
| SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | |||||
| CVE-2004-0290 | 1 Freeform Interactive | 2 Purge, Purge Jihad | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields. | |||||
| CVE-2004-0982 | 1 Mpg123 | 1 Mpg123 | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL. | |||||
| CVE-2004-0289 | 1 Paul L Daniels | 1 Signaturedb | 2017-07-11 | 2.1 LOW | N/A |
| Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter. | |||||
| CVE-2004-0288 | 1 Mnogosearch | 1 Mnogosearch | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document. | |||||
| CVE-2004-0287 | 1 Xlight Ftp Server | 1 Xlight Ftp Server | 2017-07-11 | 5.0 MEDIUM | N/A |
| Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | |||||
| CVE-2004-0286 | 1 Robotftp | 1 Robotftp Server | 2017-07-11 | 10.0 HIGH | N/A |
| Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username. | |||||
| CVE-2004-0283 | 1 Mailmgr | 1 Mailmgr | 2017-07-11 | 2.1 LOW | N/A |
| Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort. | |||||
| CVE-2004-0282 | 1 Crob | 1 Crob Ftp Server | 2017-07-11 | 5.0 MEDIUM | N/A |
| Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server. | |||||
| CVE-2004-0280 | 1 Caucho Technology | 1 Resin | 2017-07-11 | 5.0 MEDIUM | N/A |
| Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20. | |||||
| CVE-2004-0279 | 1 Aim Sniff | 1 Aim Sniff | 2017-07-11 | 7.2 HIGH | N/A |
| AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log. | |||||
| CVE-2004-0278 | 1 Ratbag | 5 Dirt Track Racing, Dirt Track Racing Australia, Dirt Track Racing Sprint Cars and 2 more | 2017-07-11 | 5.0 MEDIUM | N/A |
| Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data. | |||||
| CVE-2004-0277 | 1 Bolintech | 1 Dream Ftp Server | 2017-07-11 | 10.0 HIGH | N/A |
| Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. | |||||
| CVE-2004-0275 | 1 Bosdev | 1 Bosdates | 2017-07-11 | 5.0 MEDIUM | N/A |
| SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | |||||
| CVE-2004-0272 | 1 Maxwebportal | 1 Maxwebportal | 2017-07-11 | 7.5 HIGH | N/A |
| SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | |||||
| CVE-2004-1341 | 1 Roar Smith | 1 Info2www | 2017-07-11 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www. | |||||
| CVE-2004-1340 | 1 Debian | 1 Debian Linux | 2017-07-11 | 2.1 LOW | N/A |
| Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information. | |||||
| CVE-2004-1337 | 3 Conectiva, Gnu, Ubuntu | 3 Linux, Realtime Linux Security Module, Ubuntu Linux | 2017-07-11 | 7.2 HIGH | N/A |
| The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges. | |||||
| CVE-2004-0271 | 1 Maxwebportal | 1 Maxwebportal | 2017-07-11 | 6.8 MEDIUM | N/A |
| Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form. | |||||
| CVE-2004-0269 | 1 Francisco Burzi | 1 Php-nuke | 2017-07-11 | 6.4 MEDIUM | N/A |
| SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module. | |||||
| CVE-2004-0268 | 1 Evolutionx | 1 Evolutionx | 2017-07-11 | 5.0 MEDIUM | N/A |
| Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server. | |||||
| CVE-2004-0980 | 3 Angus Mackay, Debian, Gentoo | 3 Ez-ipupdate, Debian Linux, Linux | 2017-07-11 | 10.0 HIGH | N/A |
| Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code. | |||||
| CVE-2004-1216 | 1 Burut | 1 Kreed | 2017-07-11 | 5.0 MEDIUM | N/A |
| The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game. | |||||
| CVE-2004-0265 | 1 Francisco Burzi | 1 Php-nuke | 2017-07-11 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules. | |||||
| CVE-2004-0264 | 2 Jim Rees, Shaun2k2 | 2 Jim Rees Httpd, Palmhttpd | 2017-07-11 | 5.0 MEDIUM | N/A |
| palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. | |||||
| CVE-2004-0262 | 1 The Palace | 1 The Palace Client | 2017-07-11 | 10.0 HIGH | N/A |
| Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string. | |||||
| CVE-2004-1336 | 2 Debian, Gentoo | 2 Tetex-bin, Linux | 2017-07-11 | 2.1 LOW | N/A |
| The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack. | |||||
| CVE-2004-0260 | 1 Cactusoft | 1 Cactushop Lite | 2017-07-11 | 5.0 MEDIUM | N/A |
| The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||. | |||||
| CVE-2004-0259 | 1 Joe Lumbroso Acks | 1 Formmail.php | 2017-07-11 | 9.3 HIGH | N/A |
| The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue. | |||||
| CVE-2004-1334 | 2 Linux, Redhat | 3 Linux Kernel, Fedora Core, Linux | 2017-07-11 | 2.1 LOW | N/A |
| Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow. | |||||
| CVE-2004-0258 | 1 Realnetworks | 4 Realone Desktop Manager, Realone Enterprise Desktop, Realone Player and 1 more | 2017-07-11 | 7.6 HIGH | N/A |
| Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files. | |||||
| CVE-2004-0255 | 1 Xlight Ftp Server | 1 Xlight Ftp Server | 2017-07-11 | 5.0 MEDIUM | N/A |
| Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow. | |||||
| CVE-2004-0254 | 1 Crosscom Olicom | 1 Discuz | 2017-07-11 | 6.8 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag. | |||||
