Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0626

больше 21 года назад

The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0625

больше 21 года назад

SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0624

больше 21 года назад

PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0623

больше 21 года назад

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0622

больше 21 года назад

Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0621

больше 21 года назад

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0620

больше 21 года назад

Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0619

больше 21 года назад

Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0618

больше 21 года назад

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0617

больше 21 года назад

Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0616

больше 21 года назад

The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0615

больше 21 года назад

Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2004-0614

больше 21 года назад

osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-0613

больше 21 года назад

osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0612

больше 21 года назад

The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2004-0611

больше 21 года назад

Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0610

больше 21 года назад

The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0609

больше 21 года назад

rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0608

больше 21 года назад

The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2004-0607

больше 21 года назад

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0626

The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0625

SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0624

PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0623

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0622

Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0621

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0620

Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.

CVSS2: 4.3
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0619

Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0618

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0617

Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0616

The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0615

Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.

CVSS2: 5.1
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0614

osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.

CVSS2: 6.4
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0613

osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.

CVSS2: 7.5
10%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0612

The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.

CVSS2: 5.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0611

Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0610

The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.

CVSS2: 5
15%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0609

rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0608

The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

CVSS2: 10
74%
Высокий
больше 21 года назад
nvd логотип
CVE-2004-0607

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.

CVSS2: 10
5%
Низкий
больше 21 года назад

Уязвимостей на страницу