Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0309

больше 21 года назад

Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0308

больше 21 года назад

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0307

больше 21 года назад

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0306

больше 21 года назад

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0305

больше 21 года назад

Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0304

больше 21 года назад

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0303

больше 21 года назад

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0302

больше 21 года назад

Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0301

больше 21 года назад

Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0300

больше 21 года назад

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0299

больше 21 года назад

Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0298

больше 21 года назад

CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0297

больше 21 года назад

Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0296

больше 21 года назад

TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0295

больше 21 года назад

TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0294

больше 21 года назад

YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0293

больше 21 года назад

Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0292

больше 21 года назад

Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0291

больше 21 года назад

SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0290

больше 21 года назад

Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0309

Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.

CVSS2: 10
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0308

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0307

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0306

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0305

Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0304

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0303

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0302

Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0301

Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

CVSS2: 6.8
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0300

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

CVSS2: 10
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0299

Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0298

CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0297

Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.

CVSS2: 10
68%
Средний
больше 21 года назад
nvd логотип
CVE-2004-0296

TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0295

TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0294

YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0293

Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0292

Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

CVSS2: 10
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0291

SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0290

Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.

CVSS2: 10
6%
Низкий
больше 21 года назад

Уязвимостей на страницу