CSV
182,475 results for "vulnerability" Page 78
CVE-2004-0380

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

May 4, 2004 2 affected product(s) NVD
10.0
CVSS
63.2%
EPSS
⚡ 59
CVE-2004-0368

Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

May 4, 2004 12 affected product(s) NVD
10.0
CVSS
10.6%
EPSS
⚡ 43.2
CVE-2004-0401

Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

Jul 7, 2004 10 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2003-1048 HIGH

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Jul 27, 2004 18 affected product(s) NVD
7.8
CVSS
26.6%
EPSS
⚡ 39.2
CVE-2004-0123

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Jun 1, 2004 7 affected product(s) NVD
7.5
CVSS
29.7%
EPSS
⚡ 38.9
CVE-2004-0117

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

Jun 1, 2004 6 affected product(s) NVD
7.5
CVSS
26.5%
EPSS
⚡ 38
CVE-2003-0908

The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

Jun 1, 2004 1 affected product(s) NVD
7.2
CVSS
25.9%
EPSS
⚡ 36.6
CVE-2003-0909

Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

Jun 1, 2004 1 affected product(s) NVD
7.2
CVSS
20.9%
EPSS
⚡ 35.1
CVE-2002-1580

Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

Jun 14, 2004 6 affected product(s) NVD
7.5
CVSS
16.5%
EPSS
⚡ 35
CVE-2004-0486

HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.

Jul 7, 2004 8 affected product(s) NVD
7.6
CVSS
9.7%
EPSS
⚡ 33.3
CVE-2004-0489

Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.

Jul 7, 2004 1 affected product(s) NVD
7.6
CVSS
6.7%
EPSS
⚡ 32.4
CVE-2004-0700

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

Jul 27, 2004 44 affected product(s) NVD
7.5
CVSS
5.8%
EPSS
⚡ 31.7
CVE-2004-2036

SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.

May 28, 2004 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-2053

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

Jul 24, 2004 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2004-0717

Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

Jul 27, 2004 2 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2004-2000

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

May 5, 2004 NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-2041

PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.

May 29, 2004 NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-0703

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.

Jul 27, 2004 24 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-0707

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

Jul 27, 2004 24 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2003-0663

Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.

Jun 1, 2004 1 affected product(s) NVD
5.0
CVSS
32.0%
EPSS
⚡ 29.6