|
344201
|
5.0 |
MEDIUM
|
apple
|
mac_os_x_server
|
QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.
|
NVD-CWE-Other
|
CVE-2004-0825
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344202
|
7.5 |
HIGH
|
mozilla netscape sun hp
|
network_security_services certificate_server directory_server enterprise_server personalization_engine java_enterprise_system java_system_application_server one_application_serve…
|
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
|
NVD-CWE-Other
|
CVE-2004-0826
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344203
|
2.1 |
LOW
|
ibm
|
aix
|
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary file…
|
NVD-CWE-Other
|
CVE-2004-0828
|
2017-07-11 10:30 |
2004-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344204
|
5.0 |
MEDIUM
|
samba
|
samba
|
smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demons…
|
NVD-CWE-Other
|
CVE-2004-0829
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344205
|
5.0 |
MEDIUM
|
f-secure
|
f-secure_anti-virus f-secure_content_scanner_server internet_gatekeeper
|
The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earli…
|
NVD-CWE-Other
|
CVE-2004-0830
|
2017-07-11 10:30 |
2004-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344206
|
7.2 |
HIGH
|
mcafee
|
virusscan
|
McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain priv…
|
NVD-CWE-Other
|
CVE-2004-0831
|
2017-07-11 10:30 |
2004-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344207
|
7.5 |
HIGH
|
debian
|
debian_linux
|
Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail a…
|
NVD-CWE-Other
|
CVE-2004-0833
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344208
|
2.1 |
LOW
|
lexar
|
jumpdrive_secure
|
Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password…
|
NVD-CWE-Other
|
CVE-2004-0838
|
2017-07-11 10:30 |
2004-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344209
|
5.0 |
MEDIUM
|
gnu
|
radius
|
Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cau…
|
NVD-CWE-Other
|
CVE-2004-0849
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344210
|
7.2 |
HIGH
|
joerg_schilling
|
star_tape_archiver
|
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to refe…
|
NVD-CWE-Other
|
CVE-2004-0850
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344211
|
2.1 |
LOW
|
ulrich_callmeier
|
net-acct
|
The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2004-0851
|
2017-07-11 10:30 |
2004-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344212
|
7.5 |
HIGH
|
htget
|
htget
|
Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.
|
NVD-CWE-Other
|
CVE-2004-0852
|
2017-07-11 10:30 |
2004-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344213
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers …
|
NVD-CWE-Other
|
CVE-2004-0869
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344214
|
5.0 |
MEDIUM
|
kde
|
konqueror
|
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to s…
|
NVD-CWE-Other
|
CVE-2004-0870
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344215
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal c…
|
NVD-CWE-Other
|
CVE-2004-0871
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344216
|
7.5 |
HIGH
|
apple
|
ichat ichat_av
|
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
|
NVD-CWE-Other
|
CVE-2004-0873
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344217
|
6.8 |
MEDIUM
|
phpgroupware
|
phpgroupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a reques…
|
NVD-CWE-Other
|
CVE-2004-0875
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344218
|
1.2 |
LOW
|
getmail gentoo slackware
|
getmail linux slackware_linux
|
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
|
NVD-CWE-Other
|
CVE-2004-0880
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344219
|
2.1 |
LOW
|
getmail gentoo slackware
|
getmail linux slackware_linux
|
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
|
NVD-CWE-Other
|
CVE-2004-0881
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344220
|
7.2 |
HIGH
|
linux suse
|
linux_kernel suse_linux
|
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2004-0887
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344221
|
10.0 |
HIGH
|
easy_software_products gnome kde pdftohtml tetex xpdf debian gentoo redhat suse ubuntu
|
cups gpdf koffice kpdf pdftohtml tetex xpdf debian_linux linux kde enterprise_linux enterprise_linux_desktop fedora_core linux_advanced_workstation suse_linu…
|
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a differen…
|
NVD-CWE-Other
|
CVE-2004-0889
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344222
|
4.6 |
MEDIUM
|
mozilla
|
mozilla thunderbird
|
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow …
|
NVD-CWE-Other
|
CVE-2004-0907
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344223
|
5.1 |
MEDIUM
|
mozilla
|
mozilla thunderbird
|
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing softwar…
|
NVD-CWE-Other
|
CVE-2004-0909
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344224
|
5.0 |
MEDIUM
|
debian
|
netkit
|
telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than…
|
NVD-CWE-Other
|
CVE-2004-0911
|
2017-07-11 10:30 |
2004-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344225
|
4.6 |
MEDIUM
|
ecartis
|
ecartis
|
Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configura…
|
NVD-CWE-Other
|
CVE-2004-0913
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344226
|
5.0 |
MEDIUM
|
viewcvs debian
|
viewcvs debian_linux
|
Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote a…
|
NVD-CWE-Other
|
CVE-2004-0915
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344227
|
5.0 |
MEDIUM
|
vignette
|
application_portal
|
The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as serve…
|
NVD-CWE-Other
|
CVE-2004-0917
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344228
|
4.6 |
MEDIUM
|
freebsd
|
freebsd
|
The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.
|
NVD-CWE-Other
|
CVE-2004-0919
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344229
|
5.0 |
MEDIUM
|
symantec
|
norton_antivirus
|
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS …
|
NVD-CWE-Other
|
CVE-2004-0920
|
2017-07-11 10:30 |
2004-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344230
|
5.0 |
MEDIUM
|
hitachi macromedia
|
cosminexus_enterprise cosminexus_server coldfusion jrun
|
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, …
|
NVD-CWE-Other
|
CVE-2004-0928
|
2017-07-11 10:30 |
2004-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344231
|
10.0 |
HIGH
|
libtiff suse
|
libtiff suse_linux
|
Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to exec…
|
NVD-CWE-Other
|
CVE-2004-0929
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344232
|
5.0 |
MEDIUM
|
mysql
|
maxdb
|
MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in t…
|
NVD-CWE-Other
|
CVE-2004-0931
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344233
|
5.0 |
MEDIUM
|
neoteris
|
instant_virtual_extranet
|
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be enter…
|
NVD-CWE-Other
|
CVE-2004-0939
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344234
|
10.0 |
HIGH
|
arj_software_inc. gentoo suse
|
unarj linux suse_linux
|
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
|
NVD-CWE-Other
|
CVE-2004-0947
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344235
|
5.0 |
MEDIUM
|
danware_data
|
netop
|
NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, …
|
NVD-CWE-Other
|
CVE-2004-0950
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344236
|
10.0 |
HIGH
|
jabber_software_foundation
|
jabber_server
|
Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long…
|
NVD-CWE-Other
|
CVE-2004-0953
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344237
|
10.0 |
HIGH
|
zinf debian
|
zinf debian_linux
|
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
|
NVD-CWE-Other
|
CVE-2004-0964
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344238
|
2.1 |
LOW
|
gnu ubuntu
|
gettext ubuntu_linux
|
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to ove…
|
NVD-CWE-Other
|
CVE-2004-0966
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344239
|
2.1 |
LOW
|
gnu gentoo ubuntu
|
groff linux ubuntu_linux
|
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a sym…
|
NVD-CWE-Other
|
CVE-2004-0969
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344240
|
2.1 |
LOW
|
gnu
|
gzip
|
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: …
|
NVD-CWE-Other
|
CVE-2004-0970
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344241
|
2.1 |
LOW
|
netatalk mandrakesoft redhat
|
open_source_apple_file_share_protocol_suite mandrake_linux mandrake_linux_corporate_server fedora_core
|
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2004-0974
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344242
|
10.0 |
HIGH
|
angus_mackay debian gentoo
|
ez-ipupdate debian_linux linux
|
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0980
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344243
|
10.0 |
HIGH
|
mpg123
|
mpg123
|
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a l…
|
NVD-CWE-Other
|
CVE-2004-0982
|
2017-07-11 10:30 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344244
|
10.0 |
HIGH
|
microsoft
|
ie
|
Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .p…
|
NVD-CWE-Other
|
CVE-2004-0985
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344245
|
7.5 |
HIGH
|
suse debian linux redhat
|
suse_iptables debian_linux linux_kernel fedora_core
|
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote att…
|
NVD-CWE-Other
|
CVE-2004-0986
|
2017-07-11 10:30 |
2005-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344246
|
10.0 |
HIGH
|
proxytunnel
|
proxytunnel
|
Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.
|
NVD-CWE-Other
|
CVE-2004-0992
|
2017-07-11 10:30 |
2005-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344247
|
10.0 |
HIGH
|
hp
|
sockd
|
Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0993
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344248
|
10.0 |
HIGH
|
zgv debian
|
xzgv_image_viewer zgv_image_viewer debian_linux
|
Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demon…
|
NVD-CWE-Other
|
CVE-2004-0994
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344249
|
2.1 |
LOW
|
cscope debian gentoo sco
|
cscope debian_linux linux unixware
|
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2004-0996
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344250
|
7.5 |
HIGH
|
telnetd
|
telnetd telnetd-ssl
|
Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0998
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|