Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0039

больше 22 лет назад

Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0038

около 22 лет назад

McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0037

больше 22 лет назад

FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0036

больше 22 лет назад

SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0035

больше 22 лет назад

SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0034

больше 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-0033

больше 22 лет назад

admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0032

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0031

больше 22 лет назад

PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0030

больше 22 лет назад

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2004-0029

больше 22 лет назад

Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-0028

больше 22 лет назад

jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0017

больше 22 лет назад

Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0016

больше 22 лет назад

The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0015

больше 22 лет назад

vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0014

больше 22 лет назад

Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0013

больше 22 лет назад

jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0012

около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2004. Notes: none

EPSS: Низкий
nvd логотип

CVE-2004-0011

больше 22 лет назад

Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0010

больше 22 лет назад

Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0039

Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

CVSS2: 10
9%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0038

McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.

CVSS2: 7.5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-0037

FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0036

SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0035

SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0034

Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0033

admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0032

Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.

CVSS2: 6.8
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0031

PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0030

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

CVSS3: 9.8
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0029

Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0028

jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0017

Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0016

The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0015

vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0014

Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0013

jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0012

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2004. Notes: none

около 9 лет назад
nvd логотип
CVE-2004-0011

Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.

CVSS2: 7.5
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-0010

Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад

Уязвимостей на страницу