|
351701
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, w…
|
NVD-CWE-Other
|
CVE-2004-1084
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351702
|
2.1 |
LOW
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.
|
NVD-CWE-Other
|
CVE-2004-1085
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351703
|
7.5 |
HIGH
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
|
NVD-CWE-Other
|
CVE-2004-1086
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351704
|
2.1 |
LOW
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
|
NVD-CWE-Other
|
CVE-2004-1087
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351705
|
7.5 |
HIGH
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
|
NVD-CWE-Other
|
CVE-2004-1088
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351706
|
4.6 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.
|
NVD-CWE-Other
|
CVE-2004-1089
|
2017-07-11 10:30 |
2004-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351707
|
5.0 |
MEDIUM
|
midnight_commander debian gentoo redhat suse turbolinux
|
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation
|
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
|
NVD-CWE-Other
|
CVE-2004-1090
|
2017-07-11 10:30 |
2005-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351708
|
5.0 |
MEDIUM
|
midnight_commander debian gentoo redhat suse turbolinux
|
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation
|
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
|
NVD-CWE-Other
|
CVE-2004-1091
|
2017-07-11 10:30 |
2005-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351709
|
5.0 |
MEDIUM
|
midnight_commander debian gentoo redhat suse turbolinux
|
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation
|
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
|
NVD-CWE-Other
|
CVE-2004-1092
|
2017-07-11 10:30 |
2005-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351710
|
5.0 |
MEDIUM
|
midnight_commander debian gentoo redhat suse turbolinux
|
midnight_commander debian_linux linux enterprise_linux linux_advanced_workstation suse_linux turbolinux_server turbolinux_workstation
|
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
|
NVD-CWE-Other
|
CVE-2004-1093
|
2017-07-11 10:30 |
2005-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351711
|
10.0 |
HIGH
|
zgv debian
|
xzgv_image_viewer zgv_image_viewer debian_linux
|
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in …
|
NVD-CWE-Other
|
CVE-2004-1095
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351712
|
10.0 |
HIGH
|
cherokee
|
cherokee_httpd
|
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (a…
|
NVD-CWE-Other
|
CVE-2004-1097
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351713
|
7.5 |
HIGH
|
roaring_penguin mandrakesoft suse
|
mimedefang mandrake_linux mandrake_linux_corporate_server suse_linux
|
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
|
NVD-CWE-Other
|
CVE-2004-1098
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351714
|
6.8 |
MEDIUM
|
tips
|
mailpost
|
Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTM…
|
NVD-CWE-Other
|
CVE-2004-1100
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351715
|
6.8 |
MEDIUM
|
tips
|
mailpost
|
Successful exploitation requires that debug mode is enabled.
|
NVD-CWE-Other
|
CVE-2004-1100
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351716
|
5.8 |
MEDIUM
|
tips
|
mailpost
|
mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error messag…
|
NVD-CWE-Other
|
CVE-2004-1101
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351717
|
5.0 |
MEDIUM
|
tips
|
mailpost
|
MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allows remote attackers to gain sensitive information.
|
NVD-CWE-Other
|
CVE-2004-1102
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351718
|
5.0 |
MEDIUM
|
tips
|
mailpost
|
MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path …
|
NVD-CWE-Other
|
CVE-2004-1103
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351719
|
5.0 |
MEDIUM
|
nortel
|
contivity
|
Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.
|
NVD-CWE-Other
|
CVE-2004-1105
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351720
|
2.1 |
LOW
|
gentoo
|
linux
|
dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2004-1107
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351721
|
2.1 |
LOW
|
gentoo
|
linux
|
qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.
|
NVD-CWE-Other
|
CVE-2004-1108
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351722
|
5.0 |
MEDIUM
|
kerio
|
personal_firewall
|
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, o…
|
NVD-CWE-Other
|
CVE-2004-1109
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351723
|
2.1 |
LOW
|
jean-jacques_sarton gentoo
|
mtink linux
|
The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.
|
NVD-CWE-Other
|
CVE-2004-1110
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351724
|
5.1 |
MEDIUM
|
cisco okena
|
security_agent stormwatch
|
The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass th…
|
NVD-CWE-Other
|
CVE-2004-1112
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351725
|
10.0 |
HIGH
|
-
|
-
|
SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.
|
NVD-CWE-Other
|
CVE-2004-1113
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351726
|
9.3 |
HIGH
|
skype_technologies
|
skype
|
Buffer overflow in the handling of command line arguments in Skype 1.0.x.94 through 1.0.x.98 allows remote attackers to execute arbitrary code via a callto:// URL with a long non-existent username, a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2004-1114
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351727
|
7.2 |
HIGH
|
gentoo
|
linux
|
The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modify…
|
NVD-CWE-Other
|
CVE-2004-1115
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351728
|
7.2 |
HIGH
|
gentoo
|
linux
|
The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the progra…
|
NVD-CWE-Other
|
CVE-2004-1116
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351729
|
7.2 |
HIGH
|
gentoo
|
linux
|
The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.
|
NVD-CWE-Other
|
CVE-2004-1117
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351730
|
10.0 |
HIGH
|
weonlydo
|
wodftpdlx_activex_component
|
Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows r…
|
NVD-CWE-Other
|
CVE-2004-1118
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351731
|
10.0 |
HIGH
|
nullsoft
|
winamp
|
Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.
|
NVD-CWE-Other
|
CVE-2004-1119
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351732
|
10.0 |
HIGH
|
prozilla
|
prozilla_download_accelerator
|
Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via …
|
NVD-CWE-Other
|
CVE-2004-1120
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351733
|
5.0 |
MEDIUM
|
apple
|
safari
|
Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
|
NVD-CWE-Other
|
CVE-2004-1121
|
2017-07-11 10:30 |
2004-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351734
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server mac_os_x mac_os_x_server
|
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
|
NVD-CWE-Other
|
CVE-2004-1123
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351735
|
4.6 |
MEDIUM
|
sco
|
openserver unixware
|
Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.
|
NVD-CWE-Other
|
CVE-2004-1124
|
2017-07-11 10:30 |
2004-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351736
|
10.0 |
HIGH
|
open_dc_hub
|
direct_connect_peer-to-peer_client
|
Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.
|
NVD-CWE-Other
|
CVE-2004-1127
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351737
|
10.0 |
HIGH
|
-
|
-
|
Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename.
|
NVD-CWE-Other
|
CVE-2004-1128
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351738
|
10.0 |
HIGH
|
youngzsoft
|
cmailserver
|
SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and del…
|
NVD-CWE-Other
|
CVE-2004-1129
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351739
|
6.8 |
MEDIUM
|
youngzsoft
|
cmailserver
|
Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1) username, (2) nam…
|
NVD-CWE-Other
|
CVE-2004-1130
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351740
|
6.8 |
MEDIUM
|
youngzsoft
|
cmailserver
|
This vulnerability is addressed in the following product release:
YoungZSoft, CMailServer, 5.2.1
|
NVD-CWE-Other
|
CVE-2004-1130
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351741
|
7.2 |
HIGH
|
sco
|
openserver
|
Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.
|
NVD-CWE-Other
|
CVE-2004-1131
|
2017-07-11 10:30 |
2005-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351742
|
6.8 |
MEDIUM
|
microsoft
|
w3who.dll
|
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2…
|
NVD-CWE-Other
|
CVE-2004-1133
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351743
|
10.0 |
HIGH
|
microsoft
|
w3who.dll
|
Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.
|
NVD-CWE-Other
|
CVE-2004-1134
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351744
|
5.0 |
MEDIUM
|
ipswitch
|
ws_ftp_server
|
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
|
NVD-CWE-Other
|
CVE-2004-1135
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351745
|
5.0 |
MEDIUM
|
globalscape
|
cuteftp
|
Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.
|
NVD-CWE-Other
|
CVE-2004-1136
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351746
|
7.5 |
HIGH
|
gnu
|
mailman
|
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
|
NVD-CWE-Other
|
CVE-2004-1143
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351747
|
4.3 |
MEDIUM
|
cvstrac
|
cvstrac
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.
|
NVD-CWE-Other
|
CVE-2004-1146
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351748
|
10.0 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.
|
NVD-CWE-Other
|
CVE-2004-1147
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351749
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.
|
NVD-CWE-Other
|
CVE-2004-1148
|
2017-07-11 10:30 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351750
|
5.1 |
MEDIUM
|
nullsoft
|
winamp
|
Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, a…
|
NVD-CWE-Other
|
CVE-2004-1150
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|