CSV
182,607 results for "vulnerability" Page 112
CVE-2004-1287

Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.

Jan 10, 2005 1 affected product(s) NVD
10.0
CVSS
17.9%
EPSS
⚡ 45.4
CVE-2004-1192

Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.

Jan 10, 2005 6 affected product(s) NVD
10.0
CVSS
11.7%
EPSS
⚡ 43.5
CVE-2004-1214

Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text.

Jan 10, 2005 1 affected product(s) NVD
10.0
CVSS
6.8%
EPSS
⚡ 42.1
CVE-2004-1187

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

Jan 10, 2005 78 affected product(s) NVD
10.0
CVSS
5.2%
EPSS
⚡ 41.6
CVE-2004-1227

Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.

Jan 10, 2005 1 affected product(s) NVD
10.0
CVSS
4.2%
EPSS
⚡ 41.2
CVE-2004-1188

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

Jan 10, 2005 78 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2004-1225

SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.

Jan 10, 2005 13 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2005-0245

Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.

Feb 1, 2005 3 affected product(s) NVD
7.5
CVSS
14.5%
EPSS
⚡ 34.3
CVE-2005-0226

Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.

Feb 3, 2005 1 affected product(s) NVD
7.5
CVSS
9.7%
EPSS
⚡ 32.9
CVE-2005-0100

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

Feb 7, 2005 3 affected product(s) NVD
7.5
CVSS
4.4%
EPSS
⚡ 31.3
CVE-2005-0152

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

Feb 2, 2005 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2004-1314

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

Jan 10, 2005 7 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2005-0297

SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

Jan 18, 2005 2 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2005-0103

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

Jan 24, 2005 21 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2005-0376

PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.

Jan 12, 2005 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2004-1229

Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.

Jan 10, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-0284

SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.

Jan 10, 2005 2 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-1196

Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.

Jan 10, 2005 2 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2004-1202

Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

Jan 10, 2005 3 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2004-0957

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.

Feb 9, 2005 99 affected product(s) NVD
6.8
CVSS
2.4%
EPSS
⚡ 27.9
← Previous Page 112 of 9131 Next →