Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-2616

больше 21 года назад

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-2615

больше 21 года назад

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2614

больше 21 года назад

Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2613

больше 21 года назад

Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2612

больше 21 года назад

BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2611

больше 21 года назад

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2610

больше 21 года назад

mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2609

больше 21 года назад

The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2608

больше 21 года назад

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2607

больше 21 года назад

A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2606

больше 21 года назад

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2605

больше 21 года назад

aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2604

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2603

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2602

больше 21 года назад

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-2601

больше 21 года назад

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-2600

больше 21 года назад

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2599

больше 21 года назад

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2598

больше 21 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2597

больше 21 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2616

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.

CVSS2: 4
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2615

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2614

Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2613

Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2612

BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2611

The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2610

mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2609

The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2608

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2607

A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2606

The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2605

aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2604

Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2603

Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2602

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2601

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

CVSS2: 6.4
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2600

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2599

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2598

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2597

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

CVSS2: 5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу