CSV
182,553 results for "vulnerability" Page 104
CVE-2004-2441

Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."

Dec 31, 2004 3 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2453

Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors.

Dec 31, 2004 4 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2470

Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.

Dec 31, 2004 6 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2500

Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

Dec 31, 2004 19 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2499

Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."

Dec 31, 2004 NVD
7.8
CVSS
1.8%
EPSS
⚡ 31.8
CVE-2004-2456

SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.

Dec 31, 2004 6 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Dec 31, 2004 21 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2004-2471

SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-2474

SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-2515

Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

Dec 31, 2004 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2004-2445

Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
8.4%
EPSS
⚡ 22.5
CVE-2004-2507

Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
7.7%
EPSS
⚡ 22.3
CVE-2004-2464

Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
3.5%
EPSS
⚡ 21.1
CVE-2004-2446

Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
2.0%
EPSS
⚡ 20.6
CVE-2004-2452

Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.

Dec 31, 2004 NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2004-2457

Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.

Dec 31, 2004 4 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2004-2460

Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

Dec 31, 2004 10 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2004-2485

Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.4
CVE-2004-2498

Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.

Dec 31, 2004 NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
CVE-2004-2506

Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file.

Dec 31, 2004 14 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
← Previous Page 104 of 9128 Next →