|
344151
|
2.1 |
LOW
|
mozilla
|
bugzilla
|
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.
|
NVD-CWE-Other
|
CVE-2004-0706
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344152
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary S…
|
NVD-CWE-Other
|
CVE-2004-0707
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344153
|
7.5 |
HIGH
|
moinmoin
|
moinmoin
|
MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.
|
NVD-CWE-Other
|
CVE-2004-0708
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344154
|
7.5 |
HIGH
|
hp
|
openview_select_access
|
HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which could allow remote attackers to bypass access restrictions.
|
NVD-CWE-Other
|
CVE-2004-0709
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344155
|
7.5 |
HIGH
|
bea
|
weblogic_server
|
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote …
|
NVD-CWE-Other
|
CVE-2004-0711
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344156
|
4.6 |
MEDIUM
|
bea
|
weblogic_server
|
The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartex…
|
NVD-CWE-Other
|
CVE-2004-0712
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344157
|
6.4 |
MEDIUM
|
bea
|
weblogic_server
|
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permis…
|
NVD-CWE-Other
|
CVE-2004-0713
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344158
|
5.1 |
MEDIUM
|
bea
|
weblogic_server
|
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can c…
|
NVD-CWE-Other
|
CVE-2004-0715
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344159
|
7.5 |
HIGH
|
apple
|
safari
|
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame i…
|
NVD-CWE-Other
|
CVE-2004-0720
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344160
|
6.4 |
MEDIUM
|
microsoft
|
java_virtual_machine
|
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/K…
|
NVD-CWE-Other
|
CVE-2004-0723
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344161
|
5.0 |
MEDIUM
|
valve_software
|
half-life half-life_dedicated_server
|
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
|
NVD-CWE-Other
|
CVE-2004-0724
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344162
|
5.0 |
MEDIUM
|
microsoft
|
systems_management_server
|
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that cause…
|
NVD-CWE-Other
|
CVE-2004-0728
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344163
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, whic…
|
NVD-CWE-Other
|
CVE-2004-0729
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344164
|
6.8 |
MEDIUM
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parame…
|
NVD-CWE-Other
|
CVE-2004-0730
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344165
|
6.8 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.
|
NVD-CWE-Other
|
CVE-2004-0731
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344166
|
7.5 |
HIGH
|
francisco_burzi
|
php-nuke
|
SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.
|
NVD-CWE-Other
|
CVE-2004-0732
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344167
|
7.5 |
HIGH
|
extropia
|
extropia_webstore
|
Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
|
NVD-CWE-Other
|
CVE-2004-0734
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344168
|
7.5 |
HIGH
|
electronic_arts
|
medal_of_honor_allied_assault
|
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows rem…
|
NVD-CWE-Other
|
CVE-2004-0735
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344169
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2004-0736
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344170
|
7.5 |
HIGH
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel…
|
NVD-CWE-Other
|
CVE-2004-0737
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344171
|
7.5 |
HIGH
|
francisco_burzi
|
php-nuke
|
Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.
|
NVD-CWE-Other
|
CVE-2004-0738
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344172
|
7.5 |
HIGH
|
snapfiles
|
whisper_ftp_surfer
|
Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.
|
NVD-CWE-Other
|
CVE-2004-0739
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344173
|
5.0 |
MEDIUM
|
lexmark
|
t522_network_printer
|
The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly trig…
|
NVD-CWE-Other
|
CVE-2004-0740
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344174
|
5.0 |
MEDIUM
|
lionmax_software
|
www_file_share_pro
|
LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long URL, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-0741
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344175
|
10.0 |
HIGH
|
sun
|
java_system_calendar_server
|
Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default v…
|
NVD-CWE-Other
|
CVE-2004-0742
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344176
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected after the POST data and the user uses the forward o…
|
NVD-CWE-Other
|
CVE-2004-0743
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344177
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via a "Rose Attack" that involves sending a subset of …
|
NVD-CWE-Other
|
CVE-2004-0744
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344178
|
5.0 |
MEDIUM
|
subversion gentoo
|
subversion linux
|
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1…
|
NVD-CWE-Other
|
CVE-2004-0749
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344179
|
5.0 |
MEDIUM
|
ngsec
|
stackdefender
|
NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwPro…
|
NVD-CWE-Other
|
CVE-2004-0766
|
2017-07-11 10:30 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344180
|
5.0 |
MEDIUM
|
ngsec
|
stackdefender
|
NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile …
|
NVD-CWE-Other
|
CVE-2004-0767
|
2017-07-11 10:30 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344181
|
7.5 |
HIGH
|
greg_roelofs
|
libpng3
|
libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
|
NVD-CWE-Other
|
CVE-2004-0768
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344182
|
2.1 |
LOW
|
dgen debian
|
emulator debian_linux
|
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
|
NVD-CWE-Other
|
CVE-2004-0770
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344183
|
7.8 |
HIGH
|
realnetworks
|
helix_universal_mobile_server_and_gateway helix_universal_server
|
RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length hea…
|
NVD-CWE-Other
|
CVE-2004-0774
|
2017-07-11 10:30 |
2004-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344184
|
7.5 |
HIGH
|
inter7
|
courier-imap
|
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arb…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2004-0777
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344185
|
7.5 |
HIGH
|
firebirdsql mozilla
|
firebird firefox mozilla
|
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which…
|
NVD-CWE-Other
|
CVE-2004-0779
|
2017-07-11 10:30 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344186
|
4.3 |
MEDIUM
|
icecast
|
icecast
|
Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent pa…
|
NVD-CWE-Other
|
CVE-2004-0781
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344187
|
4.3 |
MEDIUM
|
openca
|
openca
|
Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form inpu…
|
NVD-CWE-Other
|
CVE-2004-0787
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344188
|
5.0 |
MEDIUM
|
delegate dnrd don_moore maradns pliant posadis qbik team_johnlong axis
|
delegate dnrd mydns maradns pliant_dns_server posadis wingate raidendnsd 2100_network_camera 2110_network_camera 2120_network_camera 2400_video_server 2401_video_s…
|
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 a…
|
NVD-CWE-Other
|
CVE-2004-0789
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344189
|
7.2 |
HIGH
|
debian
|
bsdmainutils
|
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-0793
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344190
|
5.1 |
MEDIUM
|
luke_mewburn
|
lukemftp tnftpd
|
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0794
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344191
|
7.2 |
HIGH
|
ibm
|
db2_universal_database
|
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
|
NVD-CWE-Other
|
CVE-2004-0795
|
2017-07-11 10:30 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344192
|
7.5 |
HIGH
|
linuxprinting.org sun conectiva trustix
|
foomatic-filters java_desktop_system linux secure_linux
|
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2004-0801
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344193
|
5.1 |
MEDIUM
|
enlightenment imagemagick sun conectiva mandrakesoft redhat suse turbolinux ubuntu
|
imlib imlib2 imagemagick java_desktop_system linux mandrake_linux mandrake_linux_corporate_server enterprise_linux enterprise_linux_desktop fedora_core linux_advanced_wo…
|
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
|
NVD-CWE-Other
|
CVE-2004-0802
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344194
|
7.5 |
HIGH
|
mpg123 mandrakesoft
|
mpg123 mandrake_linux mandrake_linux_corporate_server
|
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
|
NVD-CWE-Other
|
CVE-2004-0805
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344195
|
5.0 |
MEDIUM
|
netopia
|
timbuktu_pro_mac
|
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connection…
|
NVD-CWE-Other
|
CVE-2004-0810
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344196
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service…
|
NVD-CWE-Other
|
CVE-2004-0819
|
2017-07-11 10:30 |
2004-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344197
|
4.6 |
MEDIUM
|
nullsoft
|
winamp
|
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
|
NVD-CWE-Other
|
CVE-2004-0820
|
2017-07-11 10:30 |
2004-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344198
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-0821
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344199
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.
|
NVD-CWE-Other
|
CVE-2004-0822
|
2017-07-11 10:30 |
2004-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344200
|
2.1 |
LOW
|
apple
|
mac_os_x
|
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
|
NVD-CWE-Other
|
CVE-2004-0824
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|