Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0706

около 22 лет назад

Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0705

около 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0704

около 22 лет назад

Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0703

около 22 лет назад

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0702

около 22 лет назад

DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0701

около 22 лет назад

Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0700

около 22 лет назад

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0699

почти 22 года назад

Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0698

около 22 лет назад

4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2004-0697

около 22 лет назад

Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0696

около 22 лет назад

The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0695

около 22 лет назад

Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-0694

больше 15 лет назад

Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command line processing," a different vulnerability than CVE-2004-0771. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0693

почти 22 года назад

The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0692

почти 22 года назад

The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0691

почти 22 года назад

Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-0690

почти 22 года назад

The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0689

почти 22 года назад

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2004-0688

почти 22 года назад

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0687

почти 22 года назад

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0706

Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.

CVSS2: 2.1
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0705

Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.

CVSS2: 6.8
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0704

Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0703

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0702

DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0701

Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0700

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

CVSS2: 7.5
6%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0699

Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.

CVSS2: 7.5
6%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0698

4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.

CVSS2: 3.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0697

Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sensitive information.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0696

The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0695

Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.

CVSS2: 7.5
38%
Средний
около 22 лет назад
nvd логотип
CVE-2004-0694

Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command line processing," a different vulnerability than CVE-2004-0771. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2004-0693

The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0692

The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0691

Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.

CVSS2: 7.5
15%
Средний
почти 22 года назад
nvd логотип
CVE-2004-0690

The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.

CVSS2: 4.6
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0689

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.

CVSS3: 7.1
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0688

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

CVSS2: 7.5
7%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0687

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

CVSS2: 7.5
8%
Низкий
почти 22 года назад

Уязвимостей на страницу