266811
|
- |
|
joerg_schilling
|
star_tape_archiver
|
Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to refe…
|
NVD-CWE-Other
|
CVE-2004-0850
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266812
|
- |
|
ulrich_callmeier
|
net-acct
|
The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2004-0851
|
2017-07-11 10:30 |
2004-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266813
|
- |
|
htget
|
htget
|
Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.
|
NVD-CWE-Other
|
CVE-2004-0852
|
2017-07-11 10:30 |
2004-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266814
|
- |
|
microsoft
|
ie
|
Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers …
|
NVD-CWE-Other
|
CVE-2004-0869
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266815
|
- |
|
kde
|
konqueror
|
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to s…
|
NVD-CWE-Other
|
CVE-2004-0870
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266816
|
- |
|
mozilla
|
mozilla
|
Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal c…
|
NVD-CWE-Other
|
CVE-2004-0871
|
2017-07-11 10:30 |
2004-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266817
|
- |
|
apple
|
ichat ichat_av
|
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
|
NVD-CWE-Other
|
CVE-2004-0873
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266818
|
- |
|
phpgroupware
|
phpgroupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a reques…
|
NVD-CWE-Other
|
CVE-2004-0875
|
2017-07-11 10:30 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266819
|
- |
|
getmail gentoo slackware
|
getmail linux slackware_linux
|
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
|
NVD-CWE-Other
|
CVE-2004-0880
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266820
|
- |
|
getmail gentoo slackware
|
getmail linux slackware_linux
|
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
|
NVD-CWE-Other
|
CVE-2004-0881
|
2017-07-11 10:30 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|