CSV
182,490 results for "vulnerability" Page 87
CVE-2004-0393

Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

Dec 6, 2004 5 affected product(s) NVD
10.0
CVSS
17.4%
EPSS
⚡ 45.2
CVE-2004-0480

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.

Dec 6, 2004 2 affected product(s) NVD
10.0
CVSS
8.6%
EPSS
⚡ 42.6
CVE-2004-1351

Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.

Dec 7, 2004 6 affected product(s) NVD
10.0
CVSS
6.0%
EPSS
⚡ 41.8
CVE-2004-0448

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.

Dec 6, 2004 4 affected product(s) NVD
10.0
CVSS
4.3%
EPSS
⚡ 41.3
CVE-2004-0623

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

Dec 6, 2004 7 affected product(s) NVD
10.0
CVSS
4.5%
EPSS
⚡ 41.3
CVE-2004-0477

Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447. This candidate is ONLY for the ADSL router bypass.

Dec 6, 2004 2 affected product(s) NVD
10.0
CVSS
4.1%
EPSS
⚡ 41.2
CVE-2004-0348

SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
3.3%
EPSS
⚡ 41
CVE-2004-0603

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.

Dec 6, 2004 1 affected product(s) NVD
10.0
CVSS
3.1%
EPSS
⚡ 40.9
CVE-2004-0338

SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

Nov 23, 2004 8 affected product(s) NVD
10.0
CVSS
2.4%
EPSS
⚡ 40.7
CVE-2004-0308

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

Nov 24, 2004 10 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2005-0068

The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

Dec 22, 2004 1 affected product(s) NVD
5.0
CVSS
54.4%
EPSS
⚡ 36.3
CVE-2004-0624

PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.

Dec 6, 2004 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-0625

SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.

Dec 6, 2004 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1329

Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

Dec 20, 2004 7 affected product(s) NVD
7.2
CVSS
3.3%
EPSS
⚡ 29.8
CVE-2004-0360

Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

Nov 23, 2004 4 affected product(s) NVD
7.2
CVSS
1.0%
EPSS
⚡ 29.1
CVE-2004-0359

Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.

Nov 23, 2004 2 affected product(s) NVD
6.8
CVSS
5.6%
EPSS
⚡ 28.9
CVE-2004-0834

Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.

Dec 23, 2004 22 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0358

Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Nov 23, 2004 4 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-0606

Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.

Dec 6, 2004 2 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2004-0305

Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

Nov 23, 2004 1 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8