268601
|
- |
|
microsoft
|
windows_media_player
|
The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote at…
|
NVD-CWE-Other
|
CVE-2004-1325
|
2017-07-11 10:30 |
2004-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268602
|
- |
|
ultrix
|
dxterm
|
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.
|
NVD-CWE-Other
|
CVE-2004-1326
|
2017-07-11 10:30 |
2004-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268603
|
- |
|
crystal_art_software
|
crystal_ftp
|
Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.
|
NVD-CWE-Other
|
CVE-2004-1327
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268604
|
- |
|
ibm
|
aix
|
Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
|
NVD-CWE-Other
|
CVE-2004-1330
|
2017-07-11 10:30 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268605
|
- |
|
debian gentoo
|
tetex-bin linux
|
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2004-1336
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268606
|
- |
|
gnu conectiva ubuntu
|
realtime_linux_security_module linux ubuntu_linux
|
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to g…
|
NVD-CWE-Other
|
CVE-2004-1337
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268607
|
- |
|
oracle
|
database_server oracle9i
|
The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-1338
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268608
|
- |
|
oracle
|
database_server oracle9i
|
SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the …
|
CWE-89
SQL Injection
|
CVE-2004-1339
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268609
|
- |
|
debian
|
debian_linux
|
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2004-1340
|
2017-07-11 10:30 |
2005-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268610
|
- |
|
roar_smith
|
info2www
|
Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.
|
NVD-CWE-Other
|
CVE-2004-1341
|
2017-07-11 10:30 |
2005-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|