Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2004-2495

около 21 года назад

The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2004-2494

около 21 года назад

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2493

около 21 года назад

Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-2492

около 21 года назад

Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2491

около 21 года назад

A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2004-2490

около 21 года назад

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2489

около 21 года назад

Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2488

около 21 года назад

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-2487

около 21 года назад

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-2486

около 21 года назад

The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2485

около 21 года назад

Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2484

около 21 года назад

Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2483

около 21 года назад

Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-2482

около 21 года назад

Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2481

около 21 года назад

MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2480

около 21 года назад

Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2479

около 21 года назад

Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2478

около 21 года назад

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2477

около 21 года назад

DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2476

около 21 года назад

Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.

CVSS2: 2.6
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2495

The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.

CVSS2: 7.8
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2494

Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2493

Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

CVSS2: 4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2492

Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.

CVSS2: 4.3
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2491

A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

CVSS2: 2.6
10%
Средний
около 21 года назад
nvd логотип
CVE-2004-2490

Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2489

Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2488

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.

CVSS2: 4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2487

Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

CVSS2: 4
4%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2486

The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2485

Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2484

Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2483

Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).

CVSS2: 6.4
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2482

Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.

CVSS2: 5
21%
Средний
около 21 года назад
nvd логотип
CVE-2004-2481

MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2480

Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2479

Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2477

DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2476

Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.

CVSS2: 2.6
17%
Средний
около 21 года назад

Уязвимостей на страницу