CSV
182,580 results for "vulnerability" Page 108
CVE-2004-2644

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.

Dec 31, 2004 3 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2004-2645

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."

Dec 31, 2004 3 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2004-2691

Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports.

Dec 31, 2004 4 affected product(s) NVD
7.1
CVSS
39.1%
EPSS
⚡ 40.1
CVE-2004-2700

Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.

Dec 31, 2004 1 affected product(s) NVD
9.0
CVSS
1.7%
EPSS
⚡ 36.5
CVE-2004-2690

Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.

Dec 31, 2004 1 affected product(s) NVD
8.5
CVSS
2.4%
EPSS
⚡ 34.7
CVE-2004-2745

Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

Dec 31, 2004 1 affected product(s) NVD
7.8
CVSS
2.8%
EPSS
⚡ 32
CVE-2004-2677

Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
6.4%
EPSS
⚡ 31.9
CVE-2004-2746

SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2004-2695

SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.

Dec 31, 2004 12 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-2672

Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2004-2653

Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-2668

SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Dec 31, 2004 NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-2737

SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2004-2686

Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

Dec 31, 2004 8 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.2
CVE-2004-2674

Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via ".." sequences in the SITE UNZIP argument.

Dec 31, 2004 1 affected product(s) NVD
6.8
CVSS
1.7%
EPSS
⚡ 27.7
CVE-2004-2667

Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

Dec 31, 2004 NVD
6.8
CVSS
1.2%
EPSS
⚡ 27.6
CVE-2004-2714

Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.

Dec 31, 2004 16 affected product(s) NVD
6.0
CVSS
1.0%
EPSS
⚡ 24.3
CVE-2004-2640

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

Dec 31, 2004 NVD
5.0
CVSS
8.1%
EPSS
⚡ 22.4
CVE-2004-2750

Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Dec 31, 2004 3 affected product(s) NVD
5.0
CVSS
6.2%
EPSS
⚡ 21.9
CVE-2004-2678

Unspecified vulnerability in HP Tru64 UNIX 5.1B PK2(BL22) and PK3(BL24), and 5.1A PK6(BL24), when using IPsec/IKE (Internet Key Exchange) with Certificates, allows remote attackers to gain privileges via unknown attack vectors.

Dec 31, 2004 3 affected product(s) NVD
5.1
CVSS
1.2%
EPSS
⚡ 20.8
← Previous Page 108 of 9129 Next →