|
344951
|
10.0 |
HIGH
|
ibm
|
db2_universal_database
|
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may b…
|
NVD-CWE-Other
|
CVE-2005-0417
|
2016-10-18 12:11 |
2005-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344952
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma …
|
NVD-CWE-Other
|
CVE-2005-0429
|
2016-10-18 12:11 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344953
|
5.0 |
MEDIUM
|
id_software
|
quake_3_engine
|
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly trigge…
|
NVD-CWE-Other
|
CVE-2005-0430
|
2016-10-18 12:11 |
2005-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344954
|
4.3 |
MEDIUM
|
microsoft
|
asp.net
|
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII …
|
NVD-CWE-Other
|
CVE-2005-0452
|
2016-10-18 12:11 |
2005-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344955
|
4.3 |
MEDIUM
|
oscommerce
|
oscommerce
|
Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.
|
NVD-CWE-Other
|
CVE-2005-0458
|
2016-10-18 12:11 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344956
|
2.1 |
LOW
|
alt-n
|
webadmin
|
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a mod…
|
NVD-CWE-Other
|
CVE-2005-0318
|
2016-10-18 12:10 |
2005-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344957
|
7.5 |
HIGH
|
oracle
|
database_server
|
SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0297
|
2016-10-18 12:09 |
2005-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344958
|
10.0 |
HIGH
|
squid
|
squid
|
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which…
|
NVD-CWE-Other
|
CVE-2005-0194
|
2016-10-18 12:08 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344959
|
5.0 |
MEDIUM
|
sun compaq
|
rte sdk tru64
|
The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserializ…
|
NVD-CWE-Other
|
CVE-2005-0223
|
2016-10-18 12:08 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344960
|
5.0 |
MEDIUM
|
hp
|
virtualvault
|
Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.
|
NVD-CWE-Other
|
CVE-2005-0224
|
2016-10-18 12:08 |
2005-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344961
|
7.5 |
HIGH
|
ngircd
|
ngircd
|
Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute…
|
NVD-CWE-Other
|
CVE-2005-0226
|
2016-10-18 12:08 |
2005-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344962
|
6.4 |
MEDIUM
|
nissc
|
ipsec
|
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decry…
|
NVD-CWE-Other
|
CVE-2005-0039
|
2016-10-18 12:07 |
2005-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344963
|
5.0 |
MEDIUM
|
gnu ubuntu
|
mailman ubuntu_linux
|
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote …
|
NVD-CWE-Other
|
CVE-2005-0080
|
2016-10-18 12:07 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344964
|
2.6 |
LOW
|
microsoft
|
ie
|
Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a…
|
NVD-CWE-Other
|
CVE-2005-0110
|
2016-10-18 12:07 |
2005-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344965
|
5.8 |
MEDIUM
|
microsoft
|
outlook_express
|
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2694
|
2016-10-18 12:07 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344966
|
5.0 |
MEDIUM
|
geovision
|
geohttpserver
|
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
|
NVD-CWE-Other
|
CVE-2004-2100
|
2016-10-18 12:06 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344967
|
7.5 |
HIGH
|
phorum
|
phorum
|
SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.
|
NVD-CWE-Other
|
CVE-2004-2110
|
2016-10-18 12:06 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344968
|
4.6 |
MEDIUM
|
iss
|
blackice_pc_protection
|
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users …
|
NVD-CWE-Other
|
CVE-2004-2126
|
2016-10-18 12:06 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344969
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.
|
NVD-CWE-Other
|
CVE-2004-2130
|
2016-10-18 12:06 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344970
|
2.1 |
LOW
|
linux
|
linux_kernel
|
cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decr…
|
NVD-CWE-Other
|
CVE-2004-2135
|
2016-10-18 12:06 |
2004-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344971
|
2.1 |
LOW
|
linux
|
linux_kernel
|
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryp…
|
NVD-CWE-Other
|
CVE-2004-2136
|
2016-10-18 12:06 |
2004-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344972
|
7.5 |
HIGH
|
esesix
|
thintune
|
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.
|
NVD-CWE-Other
|
CVE-2004-2052
|
2016-10-18 12:05 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344973
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1998
|
2016-10-18 12:04 |
2004-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344974
|
7.5 |
HIGH
|
tiki
|
tikiwiki_cms\/groupware
|
Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or…
|
CWE-94
Code Injection
|
CVE-2004-1926
|
2016-10-18 12:03 |
2004-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344975
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in …
|
NVD-CWE-Other
|
CVE-2004-1839
|
2016-10-18 12:01 |
2004-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344976
|
5.0 |
MEDIUM
|
-
|
-
|
HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character.
|
NVD-CWE-Other
|
CVE-2004-1858
|
2016-10-18 12:01 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344977
|
7.5 |
HIGH
|
openbsd
|
openbsd
|
PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via…
|
NVD-CWE-Other
|
CVE-2004-1799
|
2016-10-18 12:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344978
|
2.1 |
LOW
|
jera_technology
|
flash_messaging_server
|
Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.
|
NVD-CWE-Other
|
CVE-2004-1586
|
2016-10-18 11:57 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344979
|
5.0 |
MEDIUM
|
cpanel
|
cpanel
|
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.
|
NVD-CWE-Other
|
CVE-2004-1604
|
2016-10-18 11:57 |
2004-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344980
|
7.5 |
HIGH
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2…
|
NVD-CWE-Other
|
CVE-2004-1610
|
2016-10-18 11:57 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344981
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with …
|
NVD-CWE-Other
|
CVE-2004-1614
|
2016-10-18 11:57 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344982
|
5.0 |
MEDIUM
|
w-agora
|
w-agora
|
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
|
NVD-CWE-Other
|
CVE-2004-1565
|
2016-10-18 11:56 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344983
|
5.0 |
MEDIUM
|
minihttpserver.net
|
web_forums_server
|
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot sl…
|
NVD-CWE-Other
|
CVE-2004-1496
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344984
|
4.6 |
MEDIUM
|
-
|
-
|
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-1497
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344985
|
7.5 |
HIGH
|
webhost_automation
|
helm_control_panel
|
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
|
NVD-CWE-Other
|
CVE-2004-1498
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344986
|
7.5 |
HIGH
|
jelsoft
|
vbulletin
|
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
|
NVD-CWE-Other
|
CVE-2004-1515
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344987
|
7.5 |
HIGH
|
new_media_generation
|
hired_team_trial
|
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.
|
NVD-CWE-Other
|
CVE-2004-1526
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344988
|
7.5 |
HIGH
|
mediawiki
|
mediawiki
|
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary c…
|
NVD-CWE-Other
|
CVE-2004-1405
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344989
|
5.0 |
MEDIUM
|
singapore
|
image_gallery_web_application
|
Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2004-1409
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344990
|
4.3 |
MEDIUM
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing…
|
NVD-CWE-Other
|
CVE-2004-1410
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344991
|
5.0 |
MEDIUM
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.
|
NVD-CWE-Other
|
CVE-2004-1414
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344992
|
5.0 |
MEDIUM
|
korweblog
|
korweblog
|
Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng…
|
NVD-CWE-Other
|
CVE-2004-1426
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344993
|
7.5 |
HIGH
|
asante
|
fm2008_managed_ethernet_switch
|
The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.
|
NVD-CWE-Other
|
CVE-2004-1321
|
2016-10-18 11:53 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344994
|
4.4 |
MEDIUM
|
oracle
|
application_server collaboration_suite e-business_suite enterprise_manager enterprise_manager_database_control enterprise_manager_grid_control oracle10g oracle8i oracle9i
|
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-reada…
|
CWE-200
Information Exposure
|
CVE-2004-1367
|
2016-10-18 11:53 |
2004-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344995
|
2.1 |
LOW
|
gnu
|
glibc
|
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
|
NVD-CWE-Other
|
CVE-2004-1382
|
2016-10-18 11:53 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344996
|
7.5 |
HIGH
|
hylafax
|
hylafax
|
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostnam…
|
NVD-CWE-Other
|
CVE-2004-1182
|
2016-10-18 11:52 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344997
|
7.5 |
HIGH
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2…
|
NVD-CWE-Other
|
CVE-2004-1229
|
2016-10-18 11:52 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344998
|
7.2 |
HIGH
|
atari800 debian
|
atari800 debian_linux
|
Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.
|
NVD-CWE-Other
|
CVE-2004-1076
|
2016-10-18 11:51 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344999
|
7.5 |
HIGH
|
rssh gentoo
|
rssh linux
|
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) …
|
NVD-CWE-Other
|
CVE-2004-1161
|
2016-10-18 11:51 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345000
|
2.1 |
LOW
|
ssmtp
|
ssmtp
|
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.
|
NVD-CWE-Other
|
CVE-2004-0423
|
2016-10-18 11:45 |
2004-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|