|
313451
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.
|
NVD-CWE-Other
|
CVE-2004-2288
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313452
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences…
|
NVD-CWE-Other
|
CVE-2004-2294
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313453
|
6.4 |
MEDIUM
|
novell
|
internet_messaging_system netmail
|
Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store da…
|
NVD-CWE-Other
|
CVE-2004-2298
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313454
|
5.0 |
MEDIUM
|
mbedthis_software
|
mbedthis_appweb_http_server
|
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
|
NVD-CWE-Other
|
CVE-2004-2317
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313455
|
7.5 |
HIGH
|
openbsd
|
openbsd
|
OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.
|
NVD-CWE-Other
|
CVE-2004-2338
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313456
|
5.0 |
MEDIUM
|
symantec
|
enterprise_firewall gateway_security
|
The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additiona…
|
NVD-CWE-Other
|
CVE-2004-1754
|
2008-09-6 05:42 |
2004-06-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313457
|
5.0 |
MEDIUM
|
skype_technologies
|
skype
|
A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL,…
|
CWE-20
不適切な入力確認
|
CVE-2004-1777
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313458
|
4.6 |
MEDIUM
|
info_touch
|
surfnet
|
Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.
|
NVD-CWE-Other
|
CVE-2004-1780
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313459
|
4.6 |
MEDIUM
|
info_touch
|
surfnet
|
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.
|
NVD-CWE-Other
|
CVE-2004-1781
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313460
|
7.5 |
HIGH
|
-
|
-
|
Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).
|
NVD-CWE-Other
|
CVE-2004-1783
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313461
|
7.5 |
HIGH
|
invision_power_services
|
invision_board
|
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
|
NVD-CWE-Other
|
CVE-2004-1785
|
2008-09-6 05:42 |
2004-01-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313462
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to ma…
|
NVD-CWE-Other
|
CVE-2004-1788
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313463
|
7.5 |
HIGH
|
edimax
|
full_rate_adsl_router
|
The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remo…
|
NVD-CWE-Other
|
CVE-2004-1791
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313464
|
2.1 |
LOW
|
-
|
-
|
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
|
NVD-CWE-Other
|
CVE-2004-1795
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313465
|
5.0 |
MEDIUM
|
sgi
|
irix
|
The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.
|
NVD-CWE-Other
|
CVE-2004-1891
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313466
|
4.6 |
MEDIUM
|
sgi
|
irix
|
ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.
|
NVD-CWE-Other
|
CVE-2004-2001
|
2008-09-6 05:42 |
2004-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313467
|
7.5 |
HIGH
|
zen_cart
|
zen_cart
|
The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_…
|
NVD-CWE-Other
|
CVE-2004-2024
|
2008-09-6 05:42 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313468
|
7.5 |
HIGH
|
cvs
|
cvs
|
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.
|
NVD-CWE-Other
|
CVE-2004-1342
|
2008-09-6 05:41 |
2005-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313469
|
5.0 |
MEDIUM
|
cvs
|
cvs
|
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of…
|
NVD-CWE-Other
|
CVE-2004-1343
|
2008-09-6 05:41 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313470
|
7.2 |
HIGH
|
netbsd
|
netbsd
|
Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.
|
NVD-CWE-Other
|
CVE-2004-1374
|
2008-09-6 05:41 |
2004-12-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313471
|
2.6 |
LOW
|
firebirdsql mozilla
|
firebird mozilla thunderbird
|
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking th…
|
NVD-CWE-Other
|
CVE-2004-1449
|
2008-09-6 05:41 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313472
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.
|
NVD-CWE-Other
|
CVE-2004-1450
|
2008-09-6 05:41 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313473
|
2.6 |
LOW
|
mozilla
|
mozilla
|
Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facili…
|
NVD-CWE-Other
|
CVE-2004-1451
|
2008-09-6 05:41 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313474
|
4.6 |
MEDIUM
|
linux
|
linux_kernel
|
Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-0997
|
2008-09-6 05:40 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313475
|
4.6 |
MEDIUM
|
linux
|
linux_kernel
|
This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.17
|
NVD-CWE-Other
|
CVE-2004-0997
|
2008-09-6 05:40 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313476
|
5.0 |
MEDIUM
|
sco
|
openserver unixware
|
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a…
|
NVD-CWE-Other
|
CVE-2004-1039
|
2008-09-6 05:40 |
2005-01-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313477
|
5.0 |
MEDIUM
|
citrix
|
metaframe_client program_neighborhood_agent
|
Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via…
|
NVD-CWE-Other
|
CVE-2004-1077
|
2008-09-6 05:40 |
2004-04-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313478
|
7.5 |
HIGH
|
citrix
|
metaframe_client program_neighborhood_agent
|
Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote at…
|
NVD-CWE-Other
|
CVE-2004-1078
|
2008-09-6 05:40 |
2004-04-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313479
|
7.5 |
HIGH
|
netscape
|
navigator
|
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a d…
|
NVD-CWE-Other
|
CVE-2004-1160
|
2008-09-6 05:40 |
2005-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313480
|
10.0 |
HIGH
|
gfi
|
mailessentials mailsecurity
|
A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI …
|
NVD-CWE-Other
|
CVE-2004-1312
|
2008-09-6 05:40 |
2005-01-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313481
|
7.5 |
HIGH
|
apple
|
quicktime mac_os_x mac_os_x_server
|
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
|
NVD-CWE-Other
|
CVE-2004-0921
|
2008-09-6 05:39 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313482
|
5.0 |
MEDIUM
|
apple
|
quicktime mac_os_x mac_os_x_server
|
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is…
|
NVD-CWE-Other
|
CVE-2004-0922
|
2008-09-6 05:39 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313483
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
|
NVD-CWE-Other
|
CVE-2004-0924
|
2008-09-6 05:39 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313484
|
10.0 |
HIGH
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
|
NVD-CWE-Other
|
CVE-2004-0926
|
2008-09-6 05:39 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313485
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
|
NVD-CWE-Other
|
CVE-2004-0927
|
2008-09-6 05:39 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313486
|
5.0 |
MEDIUM
|
-
|
-
|
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessio…
|
NVD-CWE-Other
|
CVE-2004-0944
|
2008-09-6 05:39 |
2004-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313487
|
5.0 |
MEDIUM
|
mitel
|
mitel_3300_integrated_communication_platform
|
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large n…
|
NVD-CWE-Other
|
CVE-2004-0945
|
2008-09-6 05:39 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313488
|
5.0 |
MEDIUM
|
stonesoft
|
firewall_engine
|
The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.
|
NVD-CWE-Other
|
CVE-2004-0498
|
2008-09-6 05:38 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313489
|
7.5 |
HIGH
|
university_of_minnesota
|
gopherd
|
Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the over…
|
NVD-CWE-Other
|
CVE-2004-0560
|
2008-09-6 05:38 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313490
|
7.5 |
HIGH
|
university_of_minnesota
|
gopherd
|
Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0561
|
2008-09-6 05:38 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313491
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.
|
NVD-CWE-Other
|
CVE-2004-0017
|
2008-09-6 05:37 |
2004-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313492
|
7.5 |
HIGH
|
mod_auth_shadow
|
mod_auth_shadow
|
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.
|
CWE-264
認可・権限・アクセス制御
|
CVE-2004-0041
|
2008-09-6 05:37 |
2004-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313493
|
6.8 |
MEDIUM
|
realnetworks
|
helix_universal_mobile_server helix_universal_server
|
Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.
|
NVD-CWE-Other
|
CVE-2004-0049
|
2008-09-6 05:37 |
2004-02-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313494
|
7.5 |
HIGH
|
nortel
|
business_communications_manager 802.11_wireless_ip_gateway succession_communication_server_1000
|
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gatewa…
|
NVD-CWE-Other
|
CVE-2004-0056
|
2008-09-6 05:37 |
2004-02-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313495
|
10.0 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-0090
|
2008-09-6 05:37 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313496
|
5.0 |
MEDIUM
|
apache
|
mod_python
|
Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.
|
NVD-CWE-Other
|
CVE-2004-0096
|
2008-09-6 05:37 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313497
|
5.0 |
MEDIUM
|
gnu
|
mailman
|
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
|
NVD-CWE-Other
|
CVE-2004-0182
|
2008-09-6 05:37 |
2004-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313498
|
7.5 |
HIGH
|
phorum
|
phorum
|
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.
|
NVD-CWE-Other
|
CVE-2003-1466
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313499
|
7.2 |
HIGH
|
freebsd
|
slashem-tty
|
slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary c…
|
CWE-264
認可・権限・アクセス制御
|
CVE-2003-1474
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313500
|
2.1 |
LOW
|
cerberus
|
ftp_server
|
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.
|
NVD-CWE-Other
|
CVE-2003-1476
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|