Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-2669 | 1 Neocrome | 1 Land Down Under | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php. | |||||
CVE-2004-2670 | 1 Endonesia | 1 Endonesia | 2017-07-28 | 6.8 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module. | |||||
CVE-2004-2671 | 1 Endonesia | 1 Endonesia | 2017-07-28 | 5.0 MEDIUM | N/A |
mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters. | |||||
CVE-2004-2673 | 1 Argosoft | 1 Ftp Server | 2017-07-28 | 9.0 HIGH | N/A |
Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument. | |||||
CVE-2004-2674 | 1 Argosoft | 1 Ftp Server | 2017-07-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via ".." sequences in the SITE UNZIP argument. | |||||
CVE-2004-2675 | 1 Argosoft | 1 Ftp Server | 2017-07-28 | 6.8 MEDIUM | N/A |
ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted. | |||||
CVE-2004-2676 | 1 Webroot Software | 1 Spy Sweeper Enterprise | 2017-07-28 | 7.2 HIGH | N/A |
The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges. | |||||
CVE-2004-2678 | 1 Hp | 1 Tru64 | 2017-07-28 | 5.1 MEDIUM | N/A |
Unspecified vulnerability in HP Tru64 UNIX 5.1B PK2(BL22) and PK3(BL24), and 5.1A PK6(BL24), when using IPsec/IKE (Internet Key Exchange) with Certificates, allows remote attackers to gain privileges via unknown attack vectors. | |||||
CVE-2004-2679 | 1 Checkpoint | 1 Firewall-1 | 2017-07-28 | 7.8 HIGH | N/A |
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information. | |||||
CVE-2004-2681 | 1 Peersec Networks | 1 Matrixssl | 2017-07-28 | 7.5 HIGH | N/A |
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session. | |||||
CVE-2004-2688 | 1 Newsphp | 1 Newsphp | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358. | |||||
CVE-2004-2689 | 1 Newsphp | 1 Newsphp | 2017-07-28 | 10.0 HIGH | N/A |
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. | |||||
CVE-2004-2690 | 1 Newsphp | 1 Newsphp | 2017-07-28 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files. | |||||
CVE-2004-2691 | 1 3com | 3 3c17205-us, 3c17210-us, Superstack 3 Switch | 2017-07-28 | 7.1 HIGH | N/A |
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports. | |||||
CVE-2004-2692 | 1 Kyberdigi Labs | 1 Php-exec-dir | 2017-07-28 | 9.3 HIGH | N/A |
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function. | |||||
CVE-2004-2696 | 1 Bea | 1 Weblogic Server | 2017-07-28 | 5.5 MEDIUM | N/A |
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call. | |||||
CVE-2004-2697 | 1 Ibm | 1 Aix | 2017-07-28 | 6.9 MEDIUM | N/A |
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002. | |||||
CVE-2004-2698 | 1 Imwheel | 1 Imwheel | 2017-07-28 | 6.9 MEDIUM | N/A |
Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file. | |||||
CVE-2004-2699 | 1 Aspdotnetstorefront | 1 Aspdotnetstorefront | 2017-07-28 | 4.3 MEDIUM | N/A |
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. | |||||
CVE-2004-2701 | 1 Aspdotnetstorefront | 1 Aspdotnetstorefront | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. |