Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-0002 | 1 Gentoo | 1 Poppassd Pam | 2008-09-10 | 10.0 HIGH | N/A |
poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users. | |||||
CVE-2004-2140 | 1 Yabb | 1 Yabb | 2008-09-10 | 5.0 MEDIUM | N/A |
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable. | |||||
CVE-2004-2188 | 1 Dmxready | 1 Dmxready Site Chassis Manager | 2008-09-10 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
CVE-2004-1782 | 1 David Maciejak | 1 Athena Web Registration | 2008-09-10 | 7.5 HIGH | N/A |
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter. | |||||
CVE-2004-1880 | 1 Openldap | 1 Openldap | 2008-09-10 | 5.0 MEDIUM | N/A |
Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption). | |||||
CVE-2004-1122 | 1 Apple | 1 Safari | 2008-09-10 | 7.5 HIGH | N/A |
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314. | |||||
CVE-2004-0984 | 1 Gnu | 1 Mailutils | 2008-09-10 | 7.2 HIGH | N/A |
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges. | |||||
CVE-2004-0988 | 1 Apple | 1 Quicktime | 2008-09-10 | 5.0 MEDIUM | N/A |
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation. | |||||
CVE-2004-0925 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2008-09-10 | 5.0 MEDIUM | N/A |
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate. | |||||
CVE-2004-0991 | 2 Mpg123, Suse | 2 Mpg123, Suse Linux | 2008-09-10 | 7.5 HIGH | N/A |
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files. | |||||
CVE-2004-0086 | 1 Apple | 1 Mac Os X | 2008-09-10 | 5.0 MEDIUM | N/A |
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085. | |||||
CVE-2004-0092 | 1 Apple | 1 Mac Os X | 2008-09-10 | 10.0 HIGH | N/A |
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact. | |||||
CVE-2004-0088 | 1 Apple | 1 Mac Os X | 2008-09-10 | 2.1 LOW | N/A |
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087. | |||||
CVE-2004-0042 | 1 Beasts | 1 Vsftpd | 2008-09-10 | 5.0 MEDIUM | N/A |
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. | |||||
CVE-2004-0002 | 1 Freebsd | 1 Freebsd | 2008-09-10 | 10.0 HIGH | N/A |
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function. | |||||
CVE-2003-1220 | 1 Bea | 1 Weblogic Server | 2008-09-10 | 5.0 MEDIUM | N/A |
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL. | |||||
CVE-2003-1223 | 1 Bea | 1 Weblogic Server | 2008-09-10 | 5.0 MEDIUM | N/A |
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap. | |||||
CVE-2003-1226 | 1 Bea | 1 Weblogic Server | 2008-09-10 | 2.1 LOW | N/A |
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords. | |||||
CVE-2003-1222 | 1 Bea | 1 Weblogic Server | 2008-09-10 | 5.0 MEDIUM | N/A |
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password. | |||||
CVE-2003-1224 | 1 Bea | 1 Weblogic Server | 2008-09-10 | 2.1 LOW | N/A |
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen. |