Total
                    210374 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2004-2121 | 1 Borland Software | 1 Web Server For Corel Paradox | 2017-07-10 | 5.0 MEDIUM | N/A | 
| Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL. | |||||
| CVE-2004-2122 | 1 Intra Forum | 1 Intra Forum | 2017-07-10 | 4.3 MEDIUM | N/A | 
| Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. | |||||
| CVE-2004-2123 | 1 Nextplace | 1 E-commerce Asp Engine | 2017-07-10 | 4.3 MEDIUM | N/A | 
| Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp. | |||||
| CVE-2004-2124 | 1 Gallery Project | 1 Gallery | 2017-07-10 | 5.0 MEDIUM | N/A | 
| The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. | |||||
| CVE-2004-2125 | 1 Iss | 4 Blackice Agent Server, Blackice Pc Protection, Blackice Server Protection and 1 more | 2017-07-10 | 4.6 MEDIUM | N/A | 
| Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value. | |||||
| CVE-2004-2127 | 1 Leif M. Wright | 1 Web Blog | 2017-07-10 | 5.0 MEDIUM | N/A | 
| Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable. | |||||
| CVE-2004-2128 | 1 Brs | 1 Webweaver | 2017-07-10 | 6.8 MEDIUM | N/A | 
| Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll. | |||||
| CVE-2004-2129 | 1 Loom Software | 2 Surfnow Professional, Surfnow Standard | 2017-07-10 | 5.0 MEDIUM | N/A | 
| SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. | |||||
| CVE-2004-2131 | 1 Ibm | 2 Informix Dynamic Server, Informix Extended Parallel Server | 2017-07-10 | 7.2 HIGH | N/A | 
| Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable. | |||||
| CVE-2004-2132 | 1 Pj Cgi Neo Review | 1 Pj Cgi Neo Review | 2017-07-10 | 5.0 MEDIUM | N/A | 
| Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. | |||||
| CVE-2004-2133 | 1 Cvsup | 1 Cvsup | 2017-07-10 | 4.6 MEDIUM | N/A | 
| Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages. | |||||
| CVE-2004-2137 | 1 Microsoft | 1 Outlook Express | 2017-07-10 | 5.0 MEDIUM | N/A | 
| Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information. | |||||
| CVE-2004-2138 | 1 Allwebscripts | 1 Mysqlguest | 2017-07-10 | 6.8 MEDIUM | N/A | 
| Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field. | |||||
| CVE-2004-2139 | 1 Yabb | 1 Yabb | 2017-07-10 | 7.5 HIGH | N/A | 
| Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl. | |||||
| CVE-2004-2142 | 1 Jorg Schilling | 1 Sdd | 2017-07-10 | 10.0 HIGH | N/A | 
| Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors. | |||||
| CVE-2004-2143 | 1 Mambo | 1 Mambo Portal | 2017-07-10 | 7.5 HIGH | N/A | 
| SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option. | |||||
| CVE-2004-2144 | 1 Baal Systems | 1 Baal Smart Forms | 2017-07-10 | 7.5 HIGH | N/A | 
| Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php. | |||||
| CVE-2004-2145 | 1 Pd9 Software | 1 Megabbs | 2017-07-10 | 7.5 HIGH | N/A | 
| SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp. | |||||
| CVE-2004-2146 | 1 Pd9 Software | 1 Megabbs | 2017-07-10 | 5.0 MEDIUM | N/A | 
| CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp. | |||||
| CVE-2004-2148 | 1 Slava Astashonok | 1 Fprobe | 2017-07-10 | 7.2 HIGH | N/A | 
| Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors. | |||||
