Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0686

около 22 лет назад

Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0685

больше 21 года назад

Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0684

почти 22 года назад

WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0683

почти 22 года назад

Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0682

почти 22 года назад

comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0681

почти 22 года назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0680

почти 22 года назад

Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0679

почти 22 года назад

The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0678

почти 22 года назад

Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0677

почти 22 года назад

Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0676

почти 22 года назад

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0675

почти 22 года назад

Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0674

почти 22 года назад

Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0673

почти 22 года назад

Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0672

почти 22 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0671

почти 22 года назад

Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0670

почти 22 года назад

Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0669

почти 22 года назад

Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0668

почти 22 года назад

Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0667

почти 22 года назад

Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0686

Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.

CVSS2: 5
4%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0685

Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0684

WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0683

Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive that contains a large number of directories.

CVSS2: 5
6%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0682

comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.

CVSS2: 7.5
7%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0681

Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.

CVSS2: 6.8
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0680

Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.

CVSS2: 10
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0679

The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0678

Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.

CVSS2: 4.3
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0677

Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").

CVSS2: 5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0676

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.

CVSS2: 10
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0675

Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.

CVSS2: 6.8
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0674

Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0673

Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.

CVSS2: 6.8
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0672

Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.

CVSS2: 6.8
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0671

Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0670

Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0669

Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.

CVSS2: 7.5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0668

Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0667

Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.

CVSS2: 7.2
0%
Низкий
почти 22 года назад

Уязвимостей на страницу