CSV
182,475 results for "vulnerability" Page 74
CVE-2004-0084

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

Mar 3, 2004 9 affected product(s) NVD
10.0
CVSS
24.9%
EPSS
⚡ 47.5
CVE-2004-0083

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

Mar 3, 2004 9 affected product(s) NVD
10.0
CVSS
21.2%
EPSS
⚡ 46.4
CVE-2004-1857 Exploit

Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.

Mar 24, 2004 1 affected product(s) NVD
2.1
CVSS
86.8%
EPSS
⚡ 44.4
CVE-2003-0170

Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

Mar 29, 2004 1 affected product(s) NVD
10.0
CVSS
2.8%
EPSS
⚡ 40.9
CVE-2004-0168

Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

Mar 15, 2004 4 affected product(s) NVD
10.0
CVSS
2.2%
EPSS
⚡ 40.6
CVE-2004-0092

Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

Mar 3, 2004 2 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2004-0159

Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

Mar 15, 2004 7 affected product(s) NVD
7.5
CVSS
9.0%
EPSS
⚡ 32.7
CVE-2004-0128

PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.

Mar 3, 2004 6 affected product(s) NVD
7.5
CVSS
8.3%
EPSS
⚡ 32.5
CVE-2004-1820

PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.

Mar 15, 2004 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2004-0127

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

Mar 3, 2004 6 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2004-1864

SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.

Mar 26, 2004 2 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2003-0796

Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.

Mar 29, 2004 28 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2004-1821

SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.

Mar 15, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1826

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Mar 16, 2004 5 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1843

SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.

Mar 20, 2004 NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-0077

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

Mar 3, 2004 112 affected product(s) NVD
7.2
CVSS
2.4%
EPSS
⚡ 29.5
CVE-2003-1018

Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

Mar 29, 2004 3 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2004-0192

Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

Mar 15, 2004 1 affected product(s) NVD
6.8
CVSS
4.5%
EPSS
⚡ 28.5
CVE-2003-1199

Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.

Mar 11, 2004 1 affected product(s) NVD
6.8
CVSS
2.2%
EPSS
⚡ 27.9
CVE-2004-1818

Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.

Mar 15, 2004 NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8