Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-1461

больше 21 года назад

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1460

больше 21 года назад

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1459

больше 21 года назад

Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1458

больше 21 года назад

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1457

больше 21 года назад

The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1456

больше 21 года назад

filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-1455

больше 21 года назад

Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2004-1454

больше 21 года назад

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1453

больше 21 года назад

GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1452

больше 21 года назад

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-1451

больше 21 года назад

Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1450

больше 21 года назад

Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1449

больше 21 года назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1448

больше 21 года назад

Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1447

больше 21 года назад

Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1446

больше 21 года назад

Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1445

больше 21 года назад

A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2004-1444

больше 21 года назад

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1443

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1442

больше 21 года назад

Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1461

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1460

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1459

Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1458

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1457

The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1456

filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.

CVSS2: 7.5
14%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1455

Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.

CVSS2: 5.1
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1454

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1453

GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1452

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1451

Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1450

Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1449

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1448

Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.

CVSS2: 4.6
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1447

Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1446

Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1445

A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.

CVSS2: 3.7
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1444

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

CVSS2: 5
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1443

Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1442

Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

CVSS2: 4.3
4%
Низкий
больше 21 года назад

Уязвимостей на страницу