CSV
182,568 results for "vulnerability" Page 105
CVE-2004-2500

Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

Dec 31, 2004 19 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2537

Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

Dec 31, 2004 14 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2499

Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."

Dec 31, 2004 NVD
7.8
CVSS
1.8%
EPSS
⚡ 31.8
CVE-2004-2539

Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID

Dec 31, 2004 2 affected product(s) NVD
7.8
CVSS
1.8%
EPSS
⚡ 31.8
CVE-2004-2573

PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Dec 31, 2004 21 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2004-2558

Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."

Dec 31, 2004 10 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2004-2562

SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Dec 31, 2004 36 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2004-2515

Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

Dec 31, 2004 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2004-2523

Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

Dec 31, 2004 4 affected product(s) NVD
6.5
CVSS
5.4%
EPSS
⚡ 27.6
CVE-2004-2538

Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.

Dec 31, 2004 6 affected product(s) NVD
6.5
CVSS
2.3%
EPSS
⚡ 26.7
CVE-2004-2580

Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.

Dec 31, 2004 1 affected product(s) NVD
5.8
CVSS
1.3%
EPSS
⚡ 23.6
CVE-2004-2526

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

Dec 31, 2004 2 affected product(s) NVD
5.0
CVSS
9.3%
EPSS
⚡ 22.8
CVE-2004-2516

Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
8.4%
EPSS
⚡ 22.5
CVE-2004-2507

Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
7.7%
EPSS
⚡ 22.3
CVE-2004-2533

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
3.0%
EPSS
⚡ 20.9
CVE-2004-2543

Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
1.9%
EPSS
⚡ 20.6
CVE-2004-2545

Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2004-2485

Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.4
CVE-2004-2498

Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.

Dec 31, 2004 NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
← Previous Page 105 of 9129 Next →