Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2004-1710

больше 21 года назад

page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1709

больше 21 года назад

Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1708

больше 21 года назад

Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1707

больше 21 года назад

The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.

CVSS2: 7.2
EPSS: Средний
nvd логотип

CVE-2004-1706

больше 21 года назад

The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version string.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1705

больше 21 года назад

Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1704

больше 21 года назад

WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1703

больше 21 года назад

Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2004-1702

больше 21 года назад

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1701

больше 21 года назад

Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-1700

больше 21 года назад

Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1699

больше 21 года назад

SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1698

больше 21 года назад

The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1697

больше 21 года назад

The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1696

больше 21 года назад

EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1695

больше 21 года назад

EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1694

больше 21 года назад

Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1693

больше 21 года назад

PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1692

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1691

больше 21 года назад

The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1710

page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1709

Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token and the driver, which could allow local users to obtain the PINs of other users.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1708

Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1707

The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.

CVSS2: 7.2
12%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1706

The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via an HTTP GET request with a long version string.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1705

Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.

CVSS2: 5
26%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1704

WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1703

Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.

CVSS3: 8.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1702

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1701

Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.

CVSS2: 10
57%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1700

Cross-site scripting (XSS) vulnerability in SettingsBase.php in Pinnacle ShowCenter 1.51 build 121 allows remote attackers to inject arbitrary HTML or web script via the Skin parameter, which is echoed in an error message.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1699

SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

CVSS2: 5
10%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1698

The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.

CVSS2: 5
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1697

The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1696

EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1695

EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).

CVSS2: 10
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1694

Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1693

PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
10%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1692

Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1691

The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.

CVSS2: 5
7%
Низкий
больше 21 года назад

Уязвимостей на страницу