Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 344 103

Количество 344 103

nvd логотип

CVE-2004-0554

больше 21 года назад

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0552

больше 21 года назад

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-0551

больше 21 года назад

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0550

больше 21 года назад

Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of "." (period) characters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0549

больше 21 года назад

The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0548

больше 21 года назад

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0547

больше 21 года назад

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0545

больше 21 года назад

LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0544

больше 21 года назад

Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0543

больше 21 года назад

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0542

больше 21 года назад

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0541

больше 21 года назад

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2004-0540

больше 21 года назад

Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0539

больше 21 года назад

The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0538

больше 21 года назад

LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0537

больше 21 года назад

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0536

больше 21 года назад

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0535

больше 21 года назад

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0534

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0533

больше 21 года назад

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0554

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0552

Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

CVSS2: 7.5
16%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0551

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way handshake to the (1) Telnet, (2) HTTP, or (3) SSH services, aka "TCP-ACK DoS attack."

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0550

Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of "." (period) characters.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0549

The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.

CVSS2: 10
69%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0548

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0547

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0545

LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0544

Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0543

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.

CVSS2: 10
10%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0542

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
12%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0541

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
77%
Высокий
больше 21 года назад
nvd логотип
CVE-2004-0540

Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.

CVSS2: 10
15%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0539

The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.

CVSS2: 10
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0538

LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0537

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0536

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0535

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0534

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0533

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

CVSS2: 2.1
0%
Низкий
больше 21 года назад

Уязвимостей на страницу