Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-1212

больше 21 года назад

Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1211

больше 21 года назад

Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2004-1210

больше 21 года назад

Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-1209

больше 21 года назад

Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1208

больше 21 года назад

Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1207

больше 21 года назад

The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1206

больше 21 года назад

Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1205

больше 21 года назад

codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1204

больше 21 года назад

FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1203

больше 21 года назад

parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1202

больше 21 года назад

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-1201

больше 21 года назад

Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1200

больше 21 года назад

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1199

больше 21 года назад

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1198

больше 21 года назад

Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1197

больше 21 года назад

Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-1196

больше 21 года назад

Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-1195

больше 21 года назад

Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1194

больше 21 года назад

Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1193

больше 21 года назад

Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable.

CVSS2: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1212

Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1211

Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

CVSS2: 10
72%
Высокий
больше 21 года назад
nvd логотип
CVE-2004-1210

Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1209

Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1208

Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.

CVSS2: 10
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1207

The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1206

Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1205

codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1204

FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1203

parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1202

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1201

Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1200

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1199

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1198

Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1197

Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter.

CVSS2: 6.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1196

Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.

CVSS2: 6.8
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1195

Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1194

Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1193

Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable.

CVSS2: 6.6
0%
Низкий
больше 21 года назад

Уязвимостей на страницу