267821
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
|
NVD-CWE-Other
|
CVE-2004-1609
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267822
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the s…
|
NVD-CWE-Other
|
CVE-2004-1611
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267823
|
- |
|
saleslogix_corporation
|
saleslogix
|
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
|
NVD-CWE-Other
|
CVE-2004-1612
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267824
|
- |
|
links
|
links
|
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangl…
|
NVD-CWE-Other
|
CVE-2004-1616
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267825
|
- |
|
vypress
|
tonecast
|
Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.
|
NVD-CWE-Other
|
CVE-2004-1618
|
2017-07-11 10:31 |
2004-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267826
|
- |
|
akella
|
privateers_bounty_age_of_sail_ii
|
Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.
|
NVD-CWE-Other
|
CVE-2004-1619
|
2017-07-11 10:31 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267827
|
- |
|
s9y
|
serendipity
|
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (…
|
NVD-CWE-Other
|
CVE-2004-1620
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267828
|
- |
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
|
NVD-CWE-Other
|
CVE-2004-1622
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267829
|
- |
|
microsoft
|
windows_xp
|
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is s…
|
NVD-CWE-Other
|
CVE-2004-1623
|
2017-07-11 10:31 |
2004-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267830
|
- |
|
altiris
|
carbon_copy
|
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in C…
|
NVD-CWE-Other
|
CVE-2004-1624
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|