Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1221 1 Darryl Burgdorf 1 Weblibs 2017-07-11 5.0 MEDIUM N/A
Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.
CVE-2004-1222 1 Darryl Burgdorf 1 Weblibs 2017-07-11 10.0 HIGH N/A
weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.
CVE-2004-1223 1 F-secure 1 Policy Manager 2017-07-11 5.0 MEDIUM N/A
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.
CVE-2004-1224 1 Mtr 1 Mtr 2017-07-11 4.6 MEDIUM N/A
Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.
CVE-2004-1225 1 Sugarcrm 1 Sugarcrm 2017-07-11 10.0 HIGH N/A
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.
CVE-2004-1226 1 Sugarcrm 1 Sugarcrm 2017-07-11 5.0 MEDIUM N/A
SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.
CVE-2004-1227 1 Sugarcrm 1 Sugar Sales 2017-07-11 10.0 HIGH N/A
Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.
CVE-2004-1228 1 Sugarcrm 1 Sugar Sales 2017-07-11 6.4 MEDIUM N/A
The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
CVE-2004-1230 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2017-07-11 5.0 MEDIUM N/A
Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.
CVE-2004-1231 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2017-07-11 5.0 MEDIUM N/A
Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.
CVE-2004-1232 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2017-07-11 10.0 HIGH N/A
Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.
CVE-2004-1233 1 Gadu-gadu 1 Gadu-gadu Instant Messenger 2017-07-11 5.0 MEDIUM N/A
Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.
CVE-2004-1236 1 Netscape 1 Directory Server 2017-07-11 10.0 HIGH N/A
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.
CVE-2004-1254 1 Rarlab 1 Winrar 2017-07-11 10.0 HIGH N/A
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
CVE-2004-1255 1 2fax 1 2fax 2017-07-11 10.0 HIGH N/A
Buffer overflow in the expandtabs function in 2fax 3.04 allows remote attackers to execute arbitrary code via a text file that is converted to TIFF.
CVE-2004-1256 1 Abcmidi 1 Abcmidi 2017-07-11 10.0 HIGH N/A
Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files.
CVE-2004-1257 1 Abc2mtex 1 Abc2mtex 2017-07-11 10.0 HIGH N/A
Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files.
CVE-2004-1258 1 Moinejf 1 Abcm2ps 2017-07-11 10.0 HIGH N/A
Buffer overflow in the put_words function in subs.c for abcm2ps 3.7.20 allows remote attackers to execute arbitrary code via crafted ABC files.
CVE-2004-1259 1 Abcpp 1 Abcpp 2017-07-11 10.0 HIGH N/A
Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files.
CVE-2004-1260 1 Abctab2ps 1 Abctab2ps 2017-07-11 10.0 HIGH N/A
Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files.
CVE-2004-1261 1 Asp2php 1 Asp2php 2017-07-11 10.0 HIGH N/A
Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts.
CVE-2004-1262 1 Stuart Cunningham 1 Bsb2ppm 2017-07-11 10.0 HIGH N/A
Buffer overflow in the bsb_open_header function in libbsb for bsb2ppm 0.0.6 allows remote attackers to execute arbitrary code via crafted BSB pictures.
CVE-2004-1263 1 Changepassword 1 Changepassword 2017-07-11 7.2 HIGH N/A
changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious "make" program.
CVE-2004-1264 1 Chbg 1 Chbg 2017-07-11 10.0 HIGH N/A
Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.
CVE-2004-1265 1 Alex Dunaevsky 1 Convex 3d 2017-07-11 10.0 HIGH N/A
Buffer overflow in the readObjectChunk function in 3dsimp.cpp for the convex-tool program in Convex 3D 0.8pre1 allows remote attackers to execute arbitrary code via a crafted 3DS file.
CVE-2004-1266 1 Jacob Rhoden 1 Csv2xml 2017-07-11 10.0 HIGH N/A
Buffer overflow in the get_field_headers function in csv2xml.cpp for csv2xml 0.5.1 allows remote attackers to execute arbitrary code via a crafted CSV file.
CVE-2004-1271 1 Dxfscope 1 Dxf File Format Viewer 2017-07-11 10.0 HIGH N/A
Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.
CVE-2004-1272 1 Bolthole 1 Filter 2017-07-11 10.0 HIGH N/A
Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message.
CVE-2004-1273 1 Greed 1 Greed 2017-07-11 10.0 HIGH N/A
Buffer overflow in the DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a long filename.
CVE-2004-1274 1 Greed 1 Greed 2017-07-11 10.0 HIGH N/A
The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.
CVE-2004-1275 1 Html2hdml 1 Html2hdml 2017-07-11 10.0 HIGH N/A
Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file.
CVE-2004-1276 1 Iglooftp 1 Iglooftp 2017-07-11 2.1 LOW N/A
IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tmpnam function, before the files are opened by IglooFTP.
CVE-2004-1277 1 Iglooftp 1 Iglooftp 2017-07-11 5.0 MEDIUM N/A
The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.
CVE-2004-1278 2 Abc2ps, John Chambers 2 Abc2ps, Jcabc2ps 2017-07-11 10.0 HIGH N/A
Buffer overflow in the switch_voice function in parse.c for jcabc2ps 20040902 allows remote attackers to execute arbitrary code via a crafted ABC file.
CVE-2004-1279 1 Jpegtoavi 1 Jpegtoavi 2017-07-11 10.0 HIGH N/A
Buffer overflow in the get_file_list_stdin function in jpegtoavi 1.5 allows remote attackers to execute arbitrary code via a crafted set of JPEG files and filenames.
CVE-2004-1280 1 Junkie 1 Junkie Ftp Client 2017-07-11 10.0 HIGH N/A
The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename.
CVE-2004-1281 1 Junkie 1 Junkie Ftp Client 2017-07-11 5.0 MEDIUM N/A
The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.
CVE-2004-1282 1 Linpopup 1 Linpopup 2017-07-11 10.0 HIGH N/A
Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that is not properly handled during a Reply operation.
CVE-2004-1283 1 Mesh Viewer 1 Mesh Viewer 2017-07-11 10.0 HIGH N/A
Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files.
CVE-2004-1284 1 Mpg123 1 Mpg123 2017-07-11 10.0 HIGH N/A
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
CVE-2004-1285 1 Mplayer 1 Mplayer 2017-07-11 10.0 HIGH N/A
Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
CVE-2004-1286 1 Napshare 1 Napshare 2017-07-11 10.0 HIGH N/A
Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.
CVE-2004-1288 1 Siag 1 O3read 2017-07-11 10.0 HIGH N/A
Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.
CVE-2004-1289 1 Pcal 1 Pcal 2017-07-11 10.0 HIGH N/A
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.
CVE-2004-1290 1 William Hoggarth 1 Pgn2web 2017-07-11 10.0 HIGH N/A
Buffer overflow in the process_moves function in pgn2web.c for pgn2web 0.3 allows remote attackers to execute arbitrary code via a crafted PGN file.
CVE-2004-1291 1 Amir Malik 1 Qwik Smtpd 2017-07-11 7.5 HIGH N/A
Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.
CVE-2004-1292 1 Michael Kohn 1 Ringtonetools 2017-07-11 10.0 HIGH N/A
Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.
CVE-2004-1293 1 Rtf2latex2e 1 Rtf2latex2e 2017-07-11 10.0 HIGH N/A
Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.
CVE-2004-1294 1 Luke Mewburn 1 Tnftp 2017-07-11 5.0 MEDIUM N/A
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
CVE-2004-1295 1 Uml-utilities 1 Uml-utilities 2017-07-11 2.1 LOW N/A
The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled).