Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-1501

больше 21 года назад

The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1500

больше 21 года назад

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1499

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1498

больше 21 года назад

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1497

больше 21 года назад

Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1496

больше 21 года назад

Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1495

больше 21 года назад

The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1494

больше 21 года назад

Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1493

больше 21 года назад

Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1492

больше 21 года назад

Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1491

больше 21 года назад

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1490

больше 21 года назад

Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1489

больше 21 года назад

Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1488

больше 21 года назад

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1487

больше 21 года назад

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1486

больше 21 года назад

Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1485

больше 21 года назад

Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1484

больше 21 года назад

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1483

больше 21 года назад

Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1482

больше 21 года назад

The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1501

The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1500

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

CVSS2: 2.1
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1499

Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1498

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1497

Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1496

Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1495

The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1494

Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1493

Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1492

Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1491

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

CVSS2: 5
13%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1490

Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.

CVSS2: 2.6
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1489

Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.

CVSS2: 2.6
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1488

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

CVSS2: 5
12%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1487

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1486

Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1485

Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1484

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1483

Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1482

The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.

CVSS2: 7.5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу