Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2004-2615

около 21 года назад

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2614

около 21 года назад

Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-2613

около 21 года назад

Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2612

около 21 года назад

BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2611

около 21 года назад

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2610

около 21 года назад

mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2609

около 21 года назад

The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2608

около 21 года назад

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2607

около 21 года назад

A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2606

около 21 года назад

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2605

около 21 года назад

aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2604

около 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2603

около 21 года назад

Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2602

около 21 года назад

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-2601

около 21 года назад

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-2600

около 21 года назад

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2599

около 21 года назад

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2598

около 21 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2597

около 21 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2596

около 21 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2615

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2614

Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
14%
Средний
около 21 года назад
nvd логотип
CVE-2004-2613

Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.

CVSS2: 10
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2612

BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2611

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2610

mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2609

The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2608

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2607

A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2606

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

CVSS2: 7.5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2605

aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2604

Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2603

Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2602

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.

CVSS2: 6.8
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2601

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

CVSS2: 6.4
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2600

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2599

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2598

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2597

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2596

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

CVSS2: 5
1%
Низкий
около 21 года назад

Уязвимостей на страницу