Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 328 224

Количество 328 224

nvd логотип

CVE-2004-2653

около 21 года назад

Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2652

около 21 года назад

The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

CVSS2: 7.8
EPSS: Средний
nvd логотип

CVE-2004-2651

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2650

около 21 года назад

Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2004-2649

около 21 года назад

Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2004-2648

около 21 года назад

FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.

CVSS2: 1
EPSS: Низкий
nvd логотип

CVE-2004-2647

около 21 года назад

Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2646

около 21 года назад

The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2645

около 21 года назад

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2644

около 21 года назад

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2643

около 21 года назад

Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2004-2642

около 21 года назад

Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-2641

около 21 года назад

Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2640

около 21 года назад

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2639

около 21 года назад

Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2638

около 21 года назад

The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2637

около 21 года назад

The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-2636

около 21 года назад

TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2635

около 21 года назад

An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2634

около 21 года назад

The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.

CVSS2: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2653

Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2652

The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

CVSS2: 7.8
23%
Средний
около 21 года назад
nvd логотип
CVE-2004-2651

Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2650

Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.

CVSS2: 4.9
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2649

Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

CVSS2: 5.8
8%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2648

FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.

CVSS2: 1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2647

Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.

CVSS2: 5
11%
Средний
около 21 года назад
nvd логотип
CVE-2004-2646

The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.

CVSS2: 5
11%
Средний
около 21 года назад
nvd логотип
CVE-2004-2645

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."

CVSS2: 10
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2644

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.

CVSS2: 10
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2643

Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.

CVSS2: 3.7
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2642

Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.

CVSS2: 6.4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2641

Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2640

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

CVSS2: 5
10%
Средний
около 21 года назад
nvd логотип
CVE-2004-2639

Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2638

The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2637

The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.

CVSS2: 6.4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2636

TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.

CVSS2: 5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2635

An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2634

The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.

CVSS2: 6.2
0%
Низкий
около 21 года назад

Уязвимостей на страницу