CSV
182,488 results for "vulnerability" Page 81
CVE-2004-0450

Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.

Aug 6, 2004 4 affected product(s) NVD
10.0
CVSS
4.7%
EPSS
⚡ 41.4
CVE-2004-0640

Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.

Aug 6, 2004 3 affected product(s) NVD
10.0
CVSS
4.5%
EPSS
⚡ 41.3
CVE-2004-0676

Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.

Aug 6, 2004 3 affected product(s) NVD
10.0
CVSS
4.3%
EPSS
⚡ 41.3
CVE-2004-0521

SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
3.2%
EPSS
⚡ 40.9
CVE-2003-1042

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2003-1043

SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2004-1682

Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.

Aug 15, 2004 1 affected product(s) NVD
10.0
CVSS
2.5%
EPSS
⚡ 40.7
CVE-2004-0513

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

Aug 18, 2004 1 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-1737

SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.

Aug 16, 2004 20 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2004-1722

SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.

Aug 17, 2004 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-0518

Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.

Aug 18, 2004 8 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1732

SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.

Aug 20, 2004 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-0490

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

Aug 18, 2004 13 affected product(s) NVD
7.2
CVSS
4.5%
EPSS
⚡ 30.1
CVE-2004-0520

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.

Aug 18, 2004 21 affected product(s) NVD
6.8
CVSS
7.1%
EPSS
⚡ 29.3
CVE-2004-0529

The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.

Aug 6, 2004 1 affected product(s) NVD
7.2
CVSS
1.5%
EPSS
⚡ 29.2
CVE-2004-0453

Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.

Aug 6, 2004 3 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0536

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

Aug 6, 2004 11 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0579

Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.

Aug 6, 2004 17 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0514

Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."

Aug 18, 2004 8 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0591

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

Aug 6, 2004 1 affected product(s) NVD
6.8
CVSS
5.0%
EPSS
⚡ 28.7