Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 332 146

Количество 332 146

nvd логотип

CVE-2004-2395

около 21 года назад

Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2394

около 21 года назад

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2393

около 21 года назад

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2392

около 21 года назад

libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2391

около 21 года назад

Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2390

около 21 года назад

The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2389

около 21 года назад

Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2388

около 21 года назад

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2387

около 21 года назад

Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2386

около 21 года назад

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2385

около 21 года назад

EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2384

около 21 года назад

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2383

около 21 года назад

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2004-2382

около 21 года назад

The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2381

около 21 года назад

HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2380

около 21 года назад

Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2379

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2378

около 21 года назад

@Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2377

около 21 года назад

Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2376

около 21 года назад

Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2395

Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2394

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2393

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2392

libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2391

Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2390

The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2389

Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2388

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

CVSS2: 10
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2387

Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.

CVSS2: 7.5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2386

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2385

EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.

CVSS2: 5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2384

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2383

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

CVSS2: 5.1
15%
Средний
около 21 года назад
nvd логотип
CVE-2004-2382

The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2381

HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2380

Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2379

Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2378

@Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2377

Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2376

Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute.

CVSS2: 7.5
2%
Низкий
около 21 года назад

Уязвимостей на страницу