|
343851
|
4.3 |
MEDIUM
|
psnews
|
psnews
|
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.
|
NVD-CWE-Other
|
CVE-2004-1665
|
2017-07-11 10:31 |
2004-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343852
|
7.5 |
HIGH
|
cerulean_studios
|
trillian
|
Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.
|
NVD-CWE-Other
|
CVE-2004-1666
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343853
|
5.0 |
MEDIUM
|
gearbox_software
|
halo_combat_evolved
|
Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.
|
NVD-CWE-Other
|
CVE-2004-1667
|
2017-07-11 10:31 |
2004-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343854
|
7.5 |
HIGH
|
easyweb
|
factory_subjects_module
|
Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.
|
NVD-CWE-Other
|
CVE-2004-1668
|
2017-07-11 10:31 |
2004-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343855
|
4.3 |
MEDIUM
|
icewarp merak
|
web_mail mail_server
|
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1)…
|
NVD-CWE-Other
|
CVE-2004-1669
|
2017-07-11 10:31 |
2004-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343856
|
7.5 |
HIGH
|
icewarp merak
|
web_mail mail_server
|
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot…
|
NVD-CWE-Other
|
CVE-2004-1670
|
2017-07-11 10:31 |
2004-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343857
|
5.0 |
MEDIUM
|
icewarp
|
web_mail
|
Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topme…
|
NVD-CWE-Other
|
CVE-2004-1671
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343858
|
7.5 |
HIGH
|
icewarp
|
web_mail
|
attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the username and message ID i…
|
NVD-CWE-Other
|
CVE-2004-1672
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343859
|
7.5 |
HIGH
|
icewarp
|
web_mail
|
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text files with arbitrary content via the accountid parame…
|
NVD-CWE-Other
|
CVE-2004-1673
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343860
|
7.5 |
HIGH
|
icewarp merak
|
web_mail mail_server
|
viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move a…
|
NVD-CWE-Other
|
CVE-2004-1674
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343861
|
7.5 |
HIGH
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.
|
NVD-CWE-Other
|
CVE-2004-1676
|
2017-07-11 10:31 |
2004-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343862
|
5.0 |
MEDIUM
|
logicnow
|
perldesk
|
pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.
|
NVD-CWE-Other
|
CVE-2004-1677
|
2017-07-11 10:31 |
2004-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343863
|
5.0 |
MEDIUM
|
logicnow
|
perldesk
|
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %…
|
NVD-CWE-Other
|
CVE-2004-1678
|
2017-07-11 10:31 |
2004-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343864
|
5.0 |
MEDIUM
|
pingtel
|
xpressa
|
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly trigg…
|
NVD-CWE-Other
|
CVE-2004-1680
|
2017-07-11 10:31 |
2004-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343865
|
7.2 |
HIGH
|
qnx
|
photon_microgui rtp
|
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) comm…
|
NVD-CWE-Other
|
CVE-2004-1681
|
2017-07-11 10:31 |
2004-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343866
|
10.0 |
HIGH
|
qnx
|
rtp
|
Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.
|
NVD-CWE-Other
|
CVE-2004-1682
|
2017-07-11 10:31 |
2004-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343867
|
3.7 |
LOW
|
-
|
-
|
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.
|
NVD-CWE-Other
|
CVE-2004-1683
|
2017-07-11 10:31 |
2004-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343868
|
5.0 |
MEDIUM
|
zyxel
|
prestige zynos
|
Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.
|
NVD-CWE-Other
|
CVE-2004-1684
|
2017-07-11 10:31 |
2004-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343869
|
7.5 |
HIGH
|
smc_networks
|
smc7004vwbr smc7008abr
|
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the admin…
|
NVD-CWE-Other
|
CVE-2004-1685
|
2017-07-11 10:31 |
2004-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343870
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment …
|
NVD-CWE-Other
|
CVE-2004-1686
|
2017-07-11 10:31 |
2004-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343871
|
5.0 |
MEDIUM
|
snitz_communications
|
snitz_forums_2000
|
CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the locati…
|
NVD-CWE-Other
|
CVE-2004-1687
|
2017-07-11 10:31 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343872
|
5.0 |
MEDIUM
|
tech-noel
|
pigeon_server
|
Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.
|
NVD-CWE-Other
|
CVE-2004-1688
|
2017-07-11 10:31 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343873
|
2.1 |
LOW
|
todd_miller
|
sudo
|
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.
|
NVD-CWE-Other
|
CVE-2004-1689
|
2017-07-11 10:31 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343874
|
4.3 |
MEDIUM
|
rhinosoft
|
dns4me
|
Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.
|
NVD-CWE-Other
|
CVE-2004-1690
|
2017-07-11 10:31 |
2004-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343875
|
5.0 |
MEDIUM
|
rhinosoft
|
dns4me
|
The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.
|
NVD-CWE-Other
|
CVE-2004-1691
|
2017-07-11 10:31 |
2004-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343876
|
4.3 |
MEDIUM
|
mambo
|
mambo_open_source
|
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
|
NVD-CWE-Other
|
CVE-2004-1692
|
2017-07-11 10:31 |
2004-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343877
|
7.5 |
HIGH
|
mambo
|
mambo
|
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a UR…
|
NVD-CWE-Other
|
CVE-2004-1693
|
2017-07-11 10:31 |
2004-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343878
|
7.5 |
HIGH
|
symantec
|
on_command_ccm on_icommand
|
Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.
|
NVD-CWE-Other
|
CVE-2004-1694
|
2017-07-11 10:31 |
2004-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343879
|
10.0 |
HIGH
|
emulive
|
server4
|
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).
|
NVD-CWE-Other
|
CVE-2004-1695
|
2017-07-11 10:31 |
2004-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343880
|
5.0 |
MEDIUM
|
emulive
|
server4
|
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.
|
NVD-CWE-Other
|
CVE-2004-1696
|
2017-07-11 10:31 |
2004-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343881
|
7.5 |
HIGH
|
-
|
-
|
The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could all…
|
NVD-CWE-Other
|
CVE-2004-1697
|
2017-07-11 10:31 |
2004-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343882
|
5.0 |
MEDIUM
|
leadmind
|
popmessenger
|
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes se…
|
NVD-CWE-Other
|
CVE-2004-1698
|
2017-07-11 10:31 |
2004-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343883
|
5.0 |
MEDIUM
|
pinnacle_systems
|
showcenter
|
SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.
|
NVD-CWE-Other
|
CVE-2004-1699
|
2017-07-11 10:31 |
2004-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343884
|
4.3 |
MEDIUM
|
pinnacle_systems
|
showcenter
|
Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echo…
|
NVD-CWE-Other
|
CVE-2004-1700
|
2017-07-11 10:31 |
2004-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343885
|
10.0 |
HIGH
|
gnu
|
cfengine
|
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authen…
|
NVD-CWE-Other
|
CVE-2004-1701
|
2017-07-11 10:31 |
2004-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343886
|
5.0 |
MEDIUM
|
gnu
|
cfengine
|
The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and trigg…
|
NVD-CWE-Other
|
CVE-2004-1702
|
2017-07-11 10:31 |
2004-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343887
|
7.5 |
HIGH
|
wire_plastic_design
|
wpquiz
|
WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.
|
NVD-CWE-Other
|
CVE-2004-1704
|
2017-07-11 10:31 |
2004-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343888
|
5.0 |
MEDIUM
|
citadel
|
ux
|
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
|
NVD-CWE-Other
|
CVE-2004-1705
|
2017-07-11 10:31 |
2004-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343889
|
7.5 |
HIGH
|
u.s.robotics
|
usr808054
|
The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version s…
|
NVD-CWE-Other
|
CVE-2004-1706
|
2017-07-11 10:31 |
2004-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343890
|
7.2 |
HIGH
|
oracle
|
application_server application_server_portal database_server_lite oracle8i oracle9i
|
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, whic…
|
NVD-CWE-Other
|
CVE-2004-1707
|
2017-07-11 10:31 |
2004-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343891
|
5.0 |
MEDIUM
|
shawn_webb
|
webbsyte_chat
|
Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.
|
NVD-CWE-Other
|
CVE-2004-1708
|
2017-07-11 10:31 |
2004-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343892
|
2.1 |
LOW
|
datakey
|
rainbow_ikey2032_usb_token
|
Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other user…
|
NVD-CWE-Other
|
CVE-2004-1709
|
2017-07-11 10:31 |
2004-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343893
|
7.5 |
HIGH
|
andrew_kilpatrick
|
page_cgi
|
page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.
|
NVD-CWE-Other
|
CVE-2004-1710
|
2017-07-11 10:31 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343894
|
2.1 |
LOW
|
hp
|
process_resource_manager workload_manager
|
Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.
|
NVD-CWE-Other
|
CVE-2004-1713
|
2017-07-11 10:31 |
2004-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343895
|
5.0 |
MEDIUM
|
clearswift
|
mimesweeper_for_web
|
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
|
NVD-CWE-Other
|
CVE-2004-1715
|
2017-07-11 10:31 |
2004-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343896
|
5.0 |
MEDIUM
|
clearswift
|
mimesweeper_for_web
|
This was fixed in MIMEsweeper for Web v5.0.4.
|
NVD-CWE-Other
|
CVE-2004-1715
|
2017-07-11 10:31 |
2004-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343897
|
6.8 |
MEDIUM
|
powie
|
pforum
|
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.
|
NVD-CWE-Other
|
CVE-2004-1716
|
2017-07-11 10:31 |
2004-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343898
|
7.5 |
HIGH
|
gv
|
gv
|
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orient…
|
NVD-CWE-Other
|
CVE-2004-1717
|
2017-07-11 10:31 |
2004-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343899
|
2.1 |
LOW
|
pedestal_software
|
integrity_protection_driver
|
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
|
NVD-CWE-Other
|
CVE-2004-1718
|
2017-07-11 10:31 |
2004-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343900
|
4.3 |
MEDIUM
|
merak
|
mail_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global,…
|
NVD-CWE-Other
|
CVE-2004-1719
|
2017-07-11 10:31 |
2004-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|