Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0543

почти 22 года назад

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0542

почти 22 года назад

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0541

почти 22 года назад

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2004-0540

почти 22 года назад

Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0539

почти 22 года назад

The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0538

почти 22 года назад

LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0537

почти 22 года назад

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0536

почти 22 года назад

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0535

почти 22 года назад

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0534

почти 22 года назад

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0533

больше 21 года назад

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0530

почти 22 года назад

The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0529

почти 22 года назад

The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0528

почти 22 года назад

Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0527

почти 22 года назад

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0526

почти 22 года назад

Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0525

почти 22 года назад

HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0524

почти 22 года назад

Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0523

почти 22 года назад

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0522

почти 22 года назад

Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0543

Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.

CVSS2: 10
7%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0542

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
31%
Средний
почти 22 года назад
nvd логотип
CVE-2004-0541

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
71%
Высокий
почти 22 года назад
nvd логотип
CVE-2004-0540

Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.

CVSS2: 10
5%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0539

The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote attackers to execute arbitrary code.

CVSS2: 10
5%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0538

LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary code without warning the user.

CVSS2: 7.5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0537

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0536

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

CVSS2: 7.2
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0535

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVSS2: 2.1
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0534

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

CVSS2: 4.3
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0533

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0530

The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, which allows local users to execute arbitrary code as the PHP user by inserting shared libraries into the appropriate path.

CVSS2: 7.2
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0529

The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.

CVSS2: 7.2
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0528

Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0527

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
6%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0526

Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

CVSS2: 5
17%
Средний
почти 22 года назад
nvd логотип
CVE-2004-0525

HP Integrated Lights-Out (iLO) 1.10 and other versions before 1.55 allows remote attackers to cause a denial of service (hang) by accessing iLO using the TCP/IP reserved port zero.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0524

Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.

CVSS2: 10
5%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0523

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.

CVSS2: 10
12%
Средний
почти 22 года назад
nvd логотип
CVE-2004-0522

Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.

CVSS2: 10
3%
Низкий
почти 22 года назад

Уязвимостей на страницу