|
344051
|
7.5 |
HIGH
|
sophos
|
small_business_suite
|
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow m…
|
NVD-CWE-Other
|
CVE-2004-0552
|
2017-07-11 10:30 |
2004-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344052
|
7.5 |
HIGH
|
gnu
|
queue
|
Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0555
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344053
|
5.0 |
MEDIUM
|
cisco
|
catos catalyst_2901 catalyst_2902 catalyst_2926 catalyst_2926f catalyst_2926gl catalyst_2926gs catalyst_2926t catalyst_2948 catalyst_2948-ge-tx catalyst_2948g-l3 cata…
|
Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid…
|
NVD-CWE-Other
|
CVE-2004-0551
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344054
|
2.1 |
LOW
|
usermin webmin mandrakesoft
|
usermin webmin mandrake_linux mandrake_linux_corporate_server
|
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
|
NVD-CWE-Other
|
CVE-2004-0559
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344055
|
2.1 |
LOW
|
freenet6
|
freenet6
|
The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a usernam…
|
NVD-CWE-Other
|
CVE-2004-0563
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344056
|
2.1 |
LOW
|
roaring_penguin debian
|
pppoe debian_linux
|
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the …
|
NVD-CWE-Other
|
CVE-2004-0564
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344057
|
5.0 |
MEDIUM
|
gnu
|
radius
|
The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing …
|
NVD-CWE-Other
|
CVE-2004-0576
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344058
|
5.0 |
MEDIUM
|
qbik
|
wingate
|
WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to the wingate-internal d…
|
NVD-CWE-Other
|
CVE-2004-0577
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344059
|
5.0 |
MEDIUM
|
qbik
|
wingate
|
WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-i…
|
NVD-CWE-Other
|
CVE-2004-0578
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344060
|
7.2 |
HIGH
|
william_deich debian
|
super debian_linux
|
Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.
|
NVD-CWE-Other
|
CVE-2004-0579
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344061
|
4.6 |
MEDIUM
|
gnu mandrakesoft
|
ksymoops mandrake_linux mandrake_linux_corporate_server
|
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
|
NVD-CWE-Other
|
CVE-2004-0581
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344062
|
5.0 |
MEDIUM
|
webmin
|
webmin
|
Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module.
|
NVD-CWE-Other
|
CVE-2004-0582
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344063
|
5.0 |
MEDIUM
|
usermin webmin debian
|
usermin webmin debian_linux
|
The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs a…
|
NVD-CWE-Other
|
CVE-2004-0583
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344064
|
6.8 |
MEDIUM
|
horde
|
imp
|
Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to execute arbitrary script as other users via script or…
|
NVD-CWE-Other
|
CVE-2004-0584
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344065
|
10.0 |
HIGH
|
ibm
|
acprunner
|
acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, and (3) Download ActiveX methods.
|
NVD-CWE-Other
|
CVE-2004-0586
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344066
|
6.8 |
MEDIUM
|
usermin
|
usermin
|
Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.
|
NVD-CWE-Other
|
CVE-2004-0588
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344067
|
6.8 |
MEDIUM
|
usermin
|
usermin
|
This vulnerability is addressed in the following product update:
Usermin, Usermin, 1.080
|
NVD-CWE-Other
|
CVE-2004-0588
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344068
|
10.0 |
HIGH
|
frees_wan openswan strongswan
|
frees_wan super_frees_wan openswan strongswan
|
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authentica…
|
NVD-CWE-Other
|
CVE-2004-0590
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344069
|
6.8 |
MEDIUM
|
inter7
|
sqwebmail
|
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-ma…
|
NVD-CWE-Other
|
CVE-2004-0591
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344070
|
6.8 |
MEDIUM
|
inter7
|
sqwebmail
|
This vulnerability is addressed in the following product release:
Inter7, SqWebMail, 4.0.5
|
NVD-CWE-Other
|
CVE-2004-0591
|
2017-07-11 10:30 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344071
|
5.0 |
MEDIUM
|
suse
|
suse_linux
|
The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denia…
|
NVD-CWE-Other
|
CVE-2004-0592
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344072
|
7.5 |
HIGH
|
sygate_technologies
|
enforcer secure_enterprise
|
Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.
|
NVD-CWE-Other
|
CVE-2004-0593
|
2017-07-11 10:30 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344073
|
7.5 |
HIGH
|
distcc
|
distcc
|
distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which could allow remote attackers to bypass intended restrictions.
|
NVD-CWE-Other
|
CVE-2004-0601
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344074
|
2.1 |
LOW
|
freebsd
|
freebsd
|
The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system p…
|
NVD-CWE-Other
|
CVE-2004-0602
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344075
|
10.0 |
HIGH
|
gnu
|
gzip
|
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2004-0603
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344076
|
5.0 |
MEDIUM
|
gift-fasttrack gentoo
|
gift-fasttrack linux
|
The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
|
NVD-CWE-Other
|
CVE-2004-0604
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344077
|
5.0 |
MEDIUM
|
ircd-hybrid ircd-ratbox
|
ircd-hybrid ircd-ratbox
|
Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote a…
|
CWE-16
Configuration
|
CVE-2004-0605
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344078
|
6.8 |
MEDIUM
|
infoblox
|
dns_one_appliance
|
Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTN…
|
NVD-CWE-Other
|
CVE-2004-0606
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344079
|
10.0 |
HIGH
|
arush dreamforge epic_games infogrames ion_storm nerf_arena_blast rage_software robert_jordan running_with_scissors gentoo
|
devastation tnn_outdoors_pro_hunter unreal_engine unreal_tournament unreal_tournament_2003 unreal_tournament_2004 tacticalops x-com_enforcer deusex nerf_arena_blast mobi…
|
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earli…
|
NVD-CWE-Other
|
CVE-2004-0608
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344080
|
5.0 |
MEDIUM
|
rssh
|
rssh
|
rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.
|
NVD-CWE-Other
|
CVE-2004-0609
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344081
|
5.0 |
MEDIUM
|
microsoft
|
mn-500_wireless_base_station
|
The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.
|
NVD-CWE-Other
|
CVE-2004-0610
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344082
|
5.0 |
MEDIUM
|
netgear
|
fvs318
|
Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.
|
NVD-CWE-Other
|
CVE-2004-0611
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344083
|
5.1 |
MEDIUM
|
zonelabs
|
zonealarm
|
The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has …
|
NVD-CWE-Other
|
CVE-2004-0612
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344084
|
7.5 |
HIGH
|
osticket
|
osticket_sts
|
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
|
NVD-CWE-Other
|
CVE-2004-0613
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344085
|
6.4 |
MEDIUM
|
osticket
|
osticket_sts
|
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
|
NVD-CWE-Other
|
CVE-2004-0614
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344086
|
5.0 |
MEDIUM
|
bt
|
voyager_2000_wireless_adsl_router
|
The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.
|
NVD-CWE-Other
|
CVE-2004-0616
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344087
|
6.8 |
MEDIUM
|
arbitroweb
|
arbitroweb
|
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.
|
NVD-CWE-Other
|
CVE-2004-0617
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344088
|
2.1 |
LOW
|
freebsd
|
freebsd
|
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.
|
NVD-CWE-Other
|
CVE-2004-0618
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344089
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
|
NVD-CWE-Other
|
CVE-2004-0620
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344090
|
10.0 |
HIGH
|
zaireweb_solutions
|
newsletter_zws
|
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and the…
|
NVD-CWE-Other
|
CVE-2004-0621
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344091
|
10.0 |
HIGH
|
gnu
|
gnats
|
Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.
|
NVD-CWE-Other
|
CVE-2004-0623
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344092
|
7.5 |
HIGH
|
artmedic_webdesign
|
artmedic_links
|
PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on…
|
NVD-CWE-Other
|
CVE-2004-0624
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344093
|
7.5 |
HIGH
|
websoft
|
infinity_web
|
SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.
|
NVD-CWE-Other
|
CVE-2004-0625
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344094
|
5.0 |
MEDIUM
|
conectiva gentoo linux suse
|
linux linux_kernel suse_linux
|
The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infini…
|
NVD-CWE-Other
|
CVE-2004-0626
|
2017-07-11 10:30 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344095
|
7.5 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file …
|
NVD-CWE-Other
|
CVE-2004-0629
|
2017-07-11 10:30 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344096
|
10.0 |
HIGH
|
adobe
|
acrobat_reader
|
The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shel…
|
NVD-CWE-Other
|
CVE-2004-0630
|
2017-07-11 10:30 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344097
|
10.0 |
HIGH
|
adobe
|
acrobat_reader
|
Buffer overflow in the uudecoding feature for Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2004-0631
|
2017-07-11 10:30 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344098
|
7.5 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows remote attackers to execute arbitrary code via a file with a long extension that…
|
NVD-CWE-Other
|
CVE-2004-0632
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344099
|
10.0 |
HIGH
|
aol
|
instant_messenger
|
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.
|
NVD-CWE-Other
|
CVE-2004-0636
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344100
|
8.5 |
HIGH
|
oracle
|
oracle8i oracle9i
|
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2004-0638
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|