Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0103

больше 22 лет назад

crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0099

больше 22 лет назад

mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0098

около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2004. Notes: none

EPSS: Низкий
nvd логотип

CVE-2004-0097

больше 22 лет назад

Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0096

больше 22 лет назад

Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0095

больше 22 лет назад

McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0094

больше 22 лет назад

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0093

больше 22 лет назад

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0092

больше 22 лет назад

Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0091

больше 22 лет назад

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0090

больше 21 года назад

Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0089

больше 22 лет назад

Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0088

больше 22 лет назад

The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0087

больше 22 лет назад

The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0086

больше 22 лет назад

Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0085

больше 22 лет назад

Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0084

больше 22 лет назад

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0083

больше 22 лет назад

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0082

больше 22 лет назад

The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0081

больше 21 года назад

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0103

crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0099

mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0098

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2004. Notes: none

около 9 лет назад
nvd логотип
CVE-2004-0097

Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

CVSS2: 10
10%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-0096

Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.

CVSS2: 5
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0095

McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.

CVSS2: 5
38%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-0094

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0093

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0092

Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

CVSS2: 10
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0091

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0090

Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0089

Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0088

The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0087

The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0086

Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0085

Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0084

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

CVSS2: 10
25%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-0083

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

CVSS2: 10
21%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-0082

The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0081

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVSS2: 5
7%
Низкий
больше 21 года назад

Уязвимостей на страницу