Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 309 169

Количество 309 169

nvd логотип

CVE-2004-0179

больше 21 года назад

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0178

больше 21 года назад

The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0177

больше 21 года назад

The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0176

больше 21 года назад

Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0175

около 21 года назад

Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0174

больше 21 года назад

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2004-0173

больше 21 года назад

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0172

больше 21 года назад

Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0171

больше 21 года назад

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0169

больше 21 года назад

QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0168

больше 21 года назад

Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0167

больше 21 года назад

DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0166

больше 21 года назад

Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0165

больше 21 года назад

Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0164

больше 21 года назад

KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0163

почти 21 год назад

Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0162

почти 21 год назад

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0161

почти 21 год назад

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0160

больше 21 года назад

Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0159

больше 21 года назад

Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0179

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

CVSS2: 6.8
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0178

The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0177

The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0176

Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

CVSS2: 5
69%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0175

Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-0174

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."

CVSS3: 7.5
31%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0173

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

CVSS2: 5
37%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0172

Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0171

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0169

QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0168

Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

CVSS2: 10
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0167

DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0166

Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."

CVSS2: 5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0165

Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0164

KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.

CVSS2: 5
13%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0163

Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0162

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.

CVSS2: 7.5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0161

Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.

CVSS2: 7.5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0160

Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0159

Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

CVSS2: 7.5
10%
Средний
больше 21 года назад

Уязвимостей на страницу