CSV
182,475 results for "vulnerability" Page 76
CVE-2004-1060 Exploit

Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

Apr 12, 2004 2 affected product(s) NVD
5.0
CVSS
74.7%
EPSS
⚡ 52.4
CVE-2004-0121

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

Apr 15, 2004 2 affected product(s) NVD
7.5
CVSS
47.7%
EPSS
⚡ 44.3
CVE-2003-0781

Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.

May 4, 2004 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2004-1988

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

Apr 30, 2004 11 affected product(s) NVD
7.5
CVSS
9.3%
EPSS
⚡ 32.8
CVE-2004-1989

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

Apr 30, 2004 11 affected product(s) NVD
7.5
CVSS
9.3%
EPSS
⚡ 32.8
CVE-2004-1934

PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.

Apr 15, 2004 1 affected product(s) NVD
7.5
CVSS
8.3%
EPSS
⚡ 32.5
CVE-2004-1929

SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.

Apr 13, 2004 15 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2004-1917

Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.

Apr 8, 2004 8 affected product(s) NVD
7.5
CVSS
4.1%
EPSS
⚡ 31.2
CVE-2003-1037

Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."

Apr 15, 2004 3 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-1943

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

Apr 19, 2004 18 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2004-1932

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

Apr 12, 2004 14 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-1972

SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.

Apr 26, 2004 1 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-1938

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.

Apr 19, 2004 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1952

SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.

Apr 23, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-0366

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

May 4, 2004 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2003-0257

Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

Apr 15, 2004 6 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0151

Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.

Apr 15, 2004 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-0905

Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.

Apr 15, 2004 1 affected product(s) NVD
5.0
CVSS
25.8%
EPSS
⚡ 27.7
CVE-2004-0173

Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

Apr 15, 2004 11 affected product(s) NVD
5.0
CVSS
15.8%
EPSS
⚡ 24.7
CVE-2004-1986

Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

Apr 4, 2004 11 affected product(s) NVD
5.0
CVSS
10.6%
EPSS
⚡ 23.2