CSV
182,475 results for "vulnerability" Page 77
CVE-2004-0380

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

May 4, 2004 2 affected product(s) NVD
10.0
CVSS
63.2%
EPSS
⚡ 59
CVE-2004-0368

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

May 4, 2004 12 affected product(s) NVD
10.0
CVSS
10.6%
EPSS
⚡ 43.2
CVE-2003-0781

Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.

May 4, 2004 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2004-0123

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Jun 1, 2004 7 affected product(s) NVD
7.5
CVSS
29.7%
EPSS
⚡ 38.9
CVE-2004-0117

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

Jun 1, 2004 6 affected product(s) NVD
7.5
CVSS
26.5%
EPSS
⚡ 38
CVE-2003-0908

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

Jun 1, 2004 1 affected product(s) NVD
7.2
CVSS
25.9%
EPSS
⚡ 36.6
CVE-2003-0909

Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

Jun 1, 2004 1 affected product(s) NVD
7.2
CVSS
20.9%
EPSS
⚡ 35.1
CVE-2004-1988

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

Apr 30, 2004 11 affected product(s) NVD
7.5
CVSS
9.3%
EPSS
⚡ 32.8
CVE-2004-1989

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

Apr 30, 2004 11 affected product(s) NVD
7.5
CVSS
9.3%
EPSS
⚡ 32.8
CVE-2004-1943

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

Apr 19, 2004 18 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2004-2036

SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.

May 28, 2004 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-1972

SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.

Apr 26, 2004 1 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-2000

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

May 5, 2004 NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-2041

PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.

May 29, 2004 NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-1938

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.

Apr 19, 2004 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1952

SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.

Apr 23, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-0366

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

May 4, 2004 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2003-0663

Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.

Jun 1, 2004 1 affected product(s) NVD
5.0
CVSS
32.0%
EPSS
⚡ 29.6
CVE-2004-0382

Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

May 4, 2004 2 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2004-0383

Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."

May 4, 2004 2 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9