Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2004-2535

около 21 года назад

The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2534

около 21 года назад

Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2004-2533

около 21 года назад

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2532

около 21 года назад

Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2531

около 21 года назад

X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2004-2530

около 21 года назад

Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-2529

около 21 года назад

Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2528

около 21 года назад

Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2527

около 21 года назад

The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.

CVSS2: 5.4
EPSS: Низкий
nvd логотип

CVE-2004-2526

около 21 года назад

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2525

около 21 года назад

Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2524

около 21 года назад

clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2523

около 21 года назад

Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

CVSS2: 6.5
EPSS: Средний
nvd логотип

CVE-2004-2522

около 21 года назад

Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2521

около 21 года назад

Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2520

около 21 года назад

POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-2519

около 21 года назад

Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2518

около 21 года назад

Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2517

около 21 года назад

myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2516

около 21 года назад

Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2535

The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2534

Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

CVSS2: 7.8
7%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2533

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

CVSS2: 5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2532

Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.

CVSS2: 10
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2531

X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.

CVSS2: 7.8
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2530

Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.

CVSS2: 2.6
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2529

Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2528

Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2527

The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.

CVSS2: 5.4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2526

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2525

Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2524

clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2523

Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

CVSS2: 6.5
28%
Средний
около 21 года назад
nvd логотип
CVE-2004-2522

Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

CVSS2: 4.3
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2521

Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2520

POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.

CVSS2: 4
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2519

Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2518

Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.

CVSS2: 5
13%
Средний
около 21 года назад
nvd логотип
CVE-2004-2517

myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2516

Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

CVSS2: 5
11%
Средний
около 21 года назад

Уязвимостей на страницу