Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 131

Количество 370 131

nvd логотип

CVE-2004-0345

больше 21 года назад

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0344

больше 21 года назад

Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-0343

больше 21 года назад

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0342

больше 21 года назад

WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2004-0341

больше 21 года назад

WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0340

больше 21 года назад

Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0339

больше 21 года назад

Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0338

больше 21 года назад

SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0337

больше 21 года назад

Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0336

больше 21 года назад

LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0335

больше 21 года назад

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0334

больше 21 года назад

InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0333

больше 21 года назад

Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0332

больше 21 года назад

Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0331

больше 21 года назад

Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0330

больше 21 года назад

Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2004-0329

больше 21 года назад

FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0328

больше 21 года назад

Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0327

больше 21 года назад

Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0326

больше 21 года назад

Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0345

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

CVSS2: 10
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0344

Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.

CVSS2: 6.4
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0343

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0342

WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

CVSS3: 5.5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0341

WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0340

Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0339

Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.

CVSS2: 6.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0338

SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0337

Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0336

LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0335

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0334

InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0333

Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

CVSS2: 10
24%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0332

Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.

CVSS2: 10
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0331

Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.

CVSS2: 5
16%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0330

Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

CVSS2: 10
85%
Высокий
больше 21 года назад
nvd логотип
CVE-2004-0329

FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0328

Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0327

Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0326

Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 10
63%
Средний
больше 21 года назад

Уязвимостей на страницу