Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-2396

больше 21 года назад

passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-2395

больше 21 года назад

Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2394

больше 21 года назад

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-2393

больше 21 года назад

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2392

больше 21 года назад

libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2391

больше 21 года назад

Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2390

больше 21 года назад

The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2389

больше 21 года назад

Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2388

больше 21 года назад

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2387

больше 21 года назад

Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2386

больше 21 года назад

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2385

больше 21 года назад

EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2384

больше 21 года назад

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2383

больше 21 года назад

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2004-2382

больше 21 года назад

The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2381

больше 21 года назад

HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2380

больше 21 года назад

Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2379

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2378

больше 21 года назад

@Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2377

больше 21 года назад

Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2396

passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2395

Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2394

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2393

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2392

libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2391

Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2390

The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2389

Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2388

rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2387

Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2386

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2385

EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2384

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2383

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

CVSS2: 5.1
20%
Средний
больше 21 года назад
nvd логотип
CVE-2004-2382

The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2381

HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2380

Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2379

Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in util.pl and (2) the Folder attribute in showmail.pl.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2378

@Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2377

Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.

CVSS2: 5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу