Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2004-2475

около 21 года назад

Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2474

около 21 года назад

SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2473

около 21 года назад

wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2004-2472

около 21 года назад

Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2471

около 21 года назад

SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2470

около 21 года назад

Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2469

около 21 года назад

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2468

около 21 года назад

Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2467

около 21 года назад

chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2466

около 21 года назад

chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2465

около 21 года назад

Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2464

около 21 года назад

Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2463

около 21 года назад

Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2462

около 21 года назад

cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2461

около 21 года назад

Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2460

около 21 года назад

Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2459

около 21 года назад

Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2458

около 21 года назад

Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2457

около 21 года назад

Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2456

около 21 года назад

SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2475

Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2474

SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2473

wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 1.2
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2472

Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2471

SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2470

Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.

CVSS2: 10
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2469

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2468

Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2467

chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2466

chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

CVSS2: 5
45%
Средний
около 21 года назад
nvd логотип
CVE-2004-2465

Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2464

Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2463

Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2462

cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2461

Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2460

Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2459

Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2458

Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2457

Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2456

SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.

CVSS2: 7.5
1%
Низкий
около 21 года назад

Уязвимостей на страницу