Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-1586 | 1 Jera Technology | 1 Flash Messaging Server | 2016-10-17 | 2.1 LOW | N/A |
Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected. | |||||
CVE-2004-1604 | 1 Cpanel | 1 Cpanel | 2016-10-17 | 5.0 MEDIUM | N/A |
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled. | |||||
CVE-2004-1610 | 2 Best Software, Saleslogix Corporation | 2 Saleslogix, Saleslogix | 2016-10-17 | 7.5 HIGH | N/A |
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables. | |||||
CVE-2004-1614 | 1 Mozilla | 1 Mozilla | 2016-10-17 | 5.0 MEDIUM | N/A |
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme. | |||||
CVE-2004-1565 | 1 W-agora | 1 W-agora | 2016-10-17 | 5.0 MEDIUM | N/A |
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter. | |||||
CVE-2004-1496 | 1 Minihttpserver.net | 1 Web Forums Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash). | |||||
CVE-2004-1497 | 1 Minihttpserver.net | 1 Web Forums Server | 2016-10-17 | 4.6 MEDIUM | N/A |
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |||||
CVE-2004-1498 | 1 Webhost Automation | 1 Helm Control Panel | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | |||||
CVE-2004-1515 | 1 Jelsoft | 1 Vbulletin | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php. | |||||
CVE-2004-1526 | 1 New Media Generation | 1 Hired Team Trial | 2016-10-17 | 7.5 HIGH | N/A |
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator. | |||||
CVE-2004-1405 | 1 Mediawiki | 1 Mediawiki | 2016-10-17 | 7.5 HIGH | N/A |
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code. | |||||
CVE-2004-1409 | 1 Singapore | 1 Image Gallery Web Application | 2016-10-17 | 5.0 MEDIUM | N/A |
Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2004-1410 | 1 Gadu-gadu | 1 Gadu-gadu Instant Messenger | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229. | |||||
CVE-2004-1414 | 1 Gadu-gadu | 1 Gadu-gadu Instant Messenger | 2016-10-17 | 5.0 MEDIUM | N/A |
Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images. | |||||
CVE-2004-1426 | 1 Korweblog | 1 Korweblog | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. | |||||
CVE-2004-1321 | 1 Asante | 1 Fm2008 Managed Ethernet Switch | 2016-10-17 | 7.5 HIGH | N/A |
The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access. | |||||
CVE-2004-1367 | 1 Oracle | 9 Application Server, Collaboration Suite, E-business Suite and 6 more | 2016-10-17 | 4.4 MEDIUM | N/A |
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed with the same password. | |||||
CVE-2004-1382 | 1 Gnu | 1 Glibc | 2016-10-17 | 2.1 LOW | N/A |
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968. | |||||
CVE-2004-1182 | 1 Hylafax | 1 Hylafax | 2016-10-17 | 7.5 HIGH | N/A |
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password. | |||||
CVE-2004-1229 | 1 Gadu-gadu | 1 Gadu-gadu Instant Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410. |