CSV
182,488 results for "vulnerability" Page 79
CVE-2004-0204 Exploit

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.

Aug 6, 2004 19 affected product(s) NVD
7.5
CVSS
73.0%
EPSS
⚡ 61.9
CVE-2004-0201

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

Aug 6, 2004 54 affected product(s) NVD
10.0
CVSS
45.3%
EPSS
⚡ 53.6
CVE-2004-0416

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

Aug 6, 2004 29 affected product(s) NVD
10.0
CVSS
13.2%
EPSS
⚡ 44
CVE-2004-0727

Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."

Jul 27, 2004 1 affected product(s) NVD
7.5
CVSS
39.8%
EPSS
⚡ 41.9
CVE-2004-0401

Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

Jul 7, 2004 10 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2003-1048 HIGH

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Jul 27, 2004 18 affected product(s) NVD
7.8
CVSS
26.6%
EPSS
⚡ 39.2
CVE-2004-1364

Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

Aug 4, 2004 87 affected product(s) NVD
8.5
CVSS
13.8%
EPSS
⚡ 38.1
CVE-2004-0213 HIGH

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Aug 6, 2004 3 affected product(s) NVD
7.8
CVSS
20.1%
EPSS
⚡ 37.2
CVE-2002-1580

Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

Jun 14, 2004 6 affected product(s) NVD
7.5
CVSS
16.5%
EPSS
⚡ 35
CVE-2004-0486

HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.

Jul 7, 2004 8 affected product(s) NVD
7.6
CVSS
9.7%
EPSS
⚡ 33.3
CVE-2004-0489

Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.

Jul 7, 2004 1 affected product(s) NVD
7.6
CVSS
6.7%
EPSS
⚡ 32.4
CVE-2004-0700

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

Jul 27, 2004 44 affected product(s) NVD
7.5
CVSS
5.8%
EPSS
⚡ 31.7
CVE-2004-0719

Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

Jul 27, 2004 10 affected product(s) NVD
7.5
CVSS
5.1%
EPSS
⚡ 31.5
CVE-2004-0733

Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.

Jul 27, 2004 4 affected product(s) NVD
7.5
CVSS
5.1%
EPSS
⚡ 31.5
CVE-2004-2053

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

Jul 24, 2004 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2004-2067

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

Jul 29, 2004 3 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2004-0717

Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

Jul 27, 2004 2 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2004-0718

The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

Jul 27, 2004 3 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2004-0721

Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

Jul 27, 2004 2 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2004-0732

SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.

Jul 27, 2004 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5