CVE-2004-0 to CVE-2004-999
252 CVEs with public proof-of-concept exploits.
- CVE-2004-00301 PoCPHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61…
- CVE-2004-00321 PoCCross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script…
- CVE-2004-00331 PoCadmin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.
- CVE-2004-00461 PoCCross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET…
- CVE-2004-00642 PoCsThe SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files…
- CVE-2004-00678 PoCsMultiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web…
- CVE-2004-00692 PoCsFormat string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format…
- CVE-2004-00701 PoCPHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying…
- CVE-2004-00711 PoCDirectory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read…
- CVE-2004-00721 PoCDirectory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \..…
- CVE-2004-00731 PoCPHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to…
- CVE-2004-00744 PoCsMultiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long…
- CVE-2004-00773 PoCsThe do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the…
- CVE-2004-00832 PoCsBuffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute…
- CVE-2004-00841 PoCBuffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or…
- CVE-2004-00951 PoCMcAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute…
- CVE-2004-01041 PoCMultiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
- CVE-2004-01101 PoCBuffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to…
- CVE-2004-01141 PoCThe shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and…
- CVE-2004-01201 PoCThe Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to…
- CVE-2004-01211 PoCArgument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as…
- CVE-2004-01281 PoCPHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to…
- CVE-2004-01291 PoCDirectory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via ..…
- CVE-2004-01322 PoCsMultiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code…
- CVE-2004-01582 PoCsBuffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c,…
- CVE-2004-01591 PoCFormat string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary…
- CVE-2004-01641 PoCKAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain…
- CVE-2004-01731 PoCDirectory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote…
- CVE-2004-01762 PoCsMultiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary…
- CVE-2004-01791 PoCMultiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3)…
- CVE-2004-01831 PoCTCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with…
- CVE-2004-01842 PoCsInteger underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an…
- CVE-2004-01851 PoCBuffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of…
- CVE-2004-01861 PoCsmbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that…
- CVE-2004-01881 PoCHeap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.
- CVE-2004-01891 PoCThe "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL…
- CVE-2004-01911 PoCMozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the…
- CVE-2004-01921 PoCCross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal…
- CVE-2004-01941 PoCStack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary…
- CVE-2004-02006 PoCsBuffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows…
- CVE-2004-02041 PoCDirectory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as…
- CVE-2004-02063 PoCsNetwork Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server…
- CVE-2004-02091 PoCUnknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows…
- CVE-2004-02101 PoCKEVThe POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly…
- CVE-2004-02122 PoCsStack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or…
- CVE-2004-02134 PoCsUtility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to…
- CVE-2004-02141 PoCBuffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote…
- CVE-2004-02181 PoCisakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a…
- CVE-2004-02191 PoCisakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed…
- CVE-2004-02201 PoCisakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request…
- CVE-2004-02211 PoCisakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload…
- CVE-2004-02221 PoCMultiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via…
- CVE-2004-02281 PoCInteger signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.
- CVE-2004-02307 PoCsTCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service…
- CVE-2004-02331 PoCUtempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary…
- CVE-2004-02341 PoCMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam…
- CVE-2004-02371 PoCDirectory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in…
- CVE-2004-02381 PoCMultiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME…
- CVE-2004-02391 PoCSQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via…
- CVE-2004-02412 PoCsX-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.
- CVE-2004-02421 PoCX-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.
- CVE-2004-02441 PoCCisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to…
- CVE-2004-02451 PoCWeb Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or…
- CVE-2004-02463 PoCsMultiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les…
- CVE-2004-02472 PoCsThe client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP…
- CVE-2004-02491 PoCPHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference…
- CVE-2004-02511 PoCCross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query…
- CVE-2004-02541 PoCCross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users…
- CVE-2004-02551 PoCXlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of…
- CVE-2004-02611 PoCoj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid…
- CVE-2004-02641 PoCpalmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which…
- CVE-2004-02651 PoCCross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as…
- CVE-2004-02661 PoCSQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to…
- CVE-2004-02681 PoCMultiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command…
- CVE-2004-02692 PoCsSQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain…
- CVE-2004-02702 PoCslibclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an…
- CVE-2004-02712 PoCsMultiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users…
- CVE-2004-02751 PoCSQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information…
- CVE-2004-02762 PoCsThe get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service…
- CVE-2004-02771 PoCFormat string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2004-02811 PoCCaucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via…
- CVE-2004-02821 PoCCrob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the…
- CVE-2004-02853 PoCsPHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote…
- CVE-2004-02862 PoCsBuffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2004-02871 PoCXlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument…
- CVE-2004-02901 PoCBuffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that…
- CVE-2004-02911 PoCSQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote…
- CVE-2004-02921 PoCBuffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2004-02932 PoCsDirectory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP…
- CVE-2004-02951 PoCTsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.
- CVE-2004-02973 PoCsBuffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows…
- CVE-2004-02981 PoCCesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.
- CVE-2004-02991 PoCBuffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/"…
- CVE-2004-03004 PoCsSQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1)…
- CVE-2004-03011 PoCCross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id…
- CVE-2004-03023 PoCsDirectory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter…
- CVE-2004-03033 PoCsOWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php,…
- CVE-2004-03041 PoCSQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and…
- CVE-2004-03051 PoCCross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script…
- CVE-2004-03121 PoCLinksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy…
- CVE-2004-03136 PoCsBuffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP…
- CVE-2004-03181 PoCLoad Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the…
- CVE-2004-03191 PoCCross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other…
- CVE-2004-03223 PoCsMultiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users…
- CVE-2004-03231 PoCMultiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1)…
- CVE-2004-03251 PoCTYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd,…
- CVE-2004-03264 PoCsBuffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.
- CVE-2004-03274 PoCsDirectory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot…
- CVE-2004-03307 PoCsBuffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to…
- CVE-2004-03311 PoCHeap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP…
- CVE-2004-03331 PoCBuffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote…
- CVE-2004-03371 PoCCross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other…
- CVE-2004-03401 PoCStack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows…
- CVE-2004-03431 PoCMultiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg…
- CVE-2004-03441 PoCDirectory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files…
- CVE-2004-03451 PoCBuffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.
- CVE-2004-03481 PoCSQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the…
- CVE-2004-03491 PoCDirectory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.
- CVE-2004-03532 PoCsMultiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers…
- CVE-2004-03541 PoCMultiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary…
- CVE-2004-03581 PoCCross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other…
- CVE-2004-03601 PoCUnknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.
- CVE-2004-03611 PoCThe Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a…
- CVE-2004-03623 PoCsMultiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various…
- CVE-2004-03632 PoCsStack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet…
- CVE-2004-03741 PoCInterchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL…
- CVE-2004-03751 PoCSYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1,…
- CVE-2004-03803 PoCsThe MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain…
- CVE-2004-03861 PoCBuffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a…
- CVE-2004-03891 PoCRealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests…
- CVE-2004-03901 PoCSCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote…
- CVE-2004-03932 PoCsFormat string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format…
- CVE-2004-03962 PoCsHeap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers…
- CVE-2004-03974 PoCsStack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute…
- CVE-2004-03991 PoCStack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to…
- CVE-2004-04091 PoCStack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to…
- CVE-2004-04151 PoCLinux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.
- CVE-2004-04161 PoCDouble free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote…
- CVE-2004-04241 PoCInteger overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a…
- CVE-2004-04304 PoCsStack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a…
- CVE-2004-04372 PoCsTitan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial…
- CVE-2004-04451 PoCThe SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004,…
- CVE-2004-04651 PoCDirectory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to…
- CVE-2004-04741 PoCHelp Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the…
- CVE-2004-04791 PoCInternet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and…
- CVE-2004-04841 PoCmshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a…
- CVE-2004-04861 PoCHelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code,…
- CVE-2004-04901 PoCcPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes…
- CVE-2004-04932 PoCsThe ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and…
- CVE-2004-04971 PoCUnknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
- CVE-2004-05011 PoCOutlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an…
- CVE-2004-05021 PoCOutlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the…
- CVE-2004-05102 PoCsMultiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute…
- CVE-2004-05111 PoCMultiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause…
- CVE-2004-05192 PoCsMultiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other…
- CVE-2004-05201 PoCCross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and…
- CVE-2004-05242 PoCsBuffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root…
- CVE-2004-05261 PoCUnknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with…
- CVE-2004-05271 PoCKDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt"…
- CVE-2004-05281 PoCNetscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that…
- CVE-2004-05413 PoCsBuffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM…
- CVE-2004-05442 PoCsMultiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
- CVE-2004-05481 PoCMultiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute…
- CVE-2004-05491 PoCThe WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote…
- CVE-2004-05521 PoCSophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1)…
- CVE-2004-05541 PoCLinux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that…
- CVE-2004-05572 PoCsMultiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers…
- CVE-2004-05582 PoCsThe Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service…
- CVE-2004-05671 PoCThe Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4,…
- CVE-2004-05741 PoCThe Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange…
- CVE-2004-05752 PoCsInteger overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit…
- CVE-2004-05801 PoCDHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously…
- CVE-2004-05911 PoCCross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote…
- CVE-2004-05941 PoCThe memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is…
- CVE-2004-05951 PoCThe strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when…
- CVE-2004-05974 PoCsMultiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via…
- CVE-2004-06002 PoCsBuffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via…
- CVE-2004-06051 PoCNon-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier…
- CVE-2004-06084 PoCsThe Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast…
- CVE-2004-06131 PoCosTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a…
- CVE-2004-06151 PoCCross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware…
- CVE-2004-06161 PoCThe BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive…
- CVE-2004-06171 PoCCross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL…
- CVE-2004-06181 PoCFreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned…
- CVE-2004-06201 PoCCross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject…
- CVE-2004-06211 PoCadmin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter…
- CVE-2004-06271 PoCThe check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length…
- CVE-2004-06331 PoCThe iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer…
- CVE-2004-06364 PoCsBuffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows…
- CVE-2004-06371 PoCOracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload…
- CVE-2004-06391 PoCMultiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or…
- CVE-2004-06411 PoCThomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence…
- CVE-2004-06481 PoCMozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a…
- CVE-2004-06561 PoCThe accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum…
- CVE-2004-06591 PoCBuffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.
- CVE-2004-06605 PoCsCross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1…
- CVE-2004-06641 PoCDirectory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot…
- CVE-2004-06651 PoCcsFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the…
- CVE-2004-06681 PoCWeb Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as…
- CVE-2004-06711 PoCBrightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in…
- CVE-2004-06722 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition…
- CVE-2004-06731 PoCCross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other…
- CVE-2004-06751 PoCCross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute…
- CVE-2004-06761 PoCDirectory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete…
- CVE-2004-06781 PoCCross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary…
- CVE-2004-06811 PoCMultiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3)…
- CVE-2004-06821 PoCcomersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices…
- CVE-2004-06831 PoCSymantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a compressed archive…
- CVE-2004-06911 PoCHeap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial…
- CVE-2004-06953 PoCsStack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a…
- CVE-2004-07221 PoCInteger overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier…
- CVE-2004-07251 PoCCross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or…
- CVE-2004-07271 PoCMicrosoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web…
- CVE-2004-07281 PoCThe Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of…
- CVE-2004-07332 PoCsFormat string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2004-07341 PoCWeb_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
- CVE-2004-07354 PoCsBuffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and…
- CVE-2004-07401 PoCThe HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or…
- CVE-2004-07511 PoCThe char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers…
- CVE-2004-07601 PoCMozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP…
- CVE-2004-07632 PoCsMozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses…
- CVE-2004-07691 PoCBuffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive,…
- CVE-2004-07711 PoCBuffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working…
- CVE-2004-07771 PoCFormat string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging…
- CVE-2004-07891 PoCMultiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products…
- CVE-2004-07903 PoCsMultiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP…
- CVE-2004-07911 PoCMultiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP…
- CVE-2004-07951 PoCDB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to…
- CVE-2004-07983 PoCsBuffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary…
- CVE-2004-08063 PoCscdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program…
- CVE-2004-08161 PoCInteger underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service…
- CVE-2004-08201 PoCWinamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are…
- CVE-2004-08241 PoCPPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
- CVE-2004-08351 PoCMySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original…
- CVE-2004-08411 PoCInternet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use…
- CVE-2004-08421 PoCInternet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application…
- CVE-2004-08471 PoCThe Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in…
- CVE-2004-08941 PoCLSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection…
- CVE-2004-09321 PoCMcAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote…
- CVE-2004-09331 PoCComputer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust…
- CVE-2004-09341 PoCKaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set…
- CVE-2004-09351 PoCEset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both…
- CVE-2004-09361 PoCRAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero,…
- CVE-2004-09371 PoCSophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass…
- CVE-2004-09402 PoCsBuffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to…
- CVE-2004-09421 PoCApache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a…
- CVE-2004-09531 PoCBuffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service…
- CVE-2004-09581 PoCphp_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC…
- CVE-2004-09648 PoCsBuffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary…
- CVE-2004-09891 PoCMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute…
- CVE-2004-09901 PoCInteger overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of…
- CVE-2004-09965 PoCsmain.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files…