CSV
182,499 results for "vulnerability" Page 91
CVE-2004-1486

Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.

Dec 31, 2004 NVD
10.0
CVSS
3.7%
EPSS
⚡ 41.1
CVE-2004-1463

Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.

Dec 31, 2004 13 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2004-1441

Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.

Dec 31, 2004 1 affected product(s) NVD
9.3
CVSS
6.6%
EPSS
⚡ 39.2
CVE-2004-1480

Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions.

Dec 31, 2004 17 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2004-1471

Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.

Dec 31, 2004 111 affected product(s) NVD
7.1
CVSS
7.7%
EPSS
⚡ 30.7
CVE-2004-1505

Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2004-1427

PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2004-1462

Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.

Dec 31, 2004 13 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2004-1430

SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arbitrary SQL code via the gameid parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1498

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

Dec 31, 2004 10 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1519

SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

Dec 31, 2004 NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1530

SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.

Dec 31, 2004 NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1515

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

Dec 31, 2004 11 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2004-1469

Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.

Dec 31, 2004 2 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2004-1419

PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.

Dec 31, 2004 3 affected product(s) NVD
6.8
CVSS
2.4%
EPSS
⚡ 27.9
CVE-2004-1444

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

Dec 31, 2004 46 affected product(s) NVD
5.0
CVSS
8.8%
EPSS
⚡ 22.6
CVE-2004-1484

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

Dec 31, 2004 16 affected product(s) NVD
5.0
CVSS
7.3%
EPSS
⚡ 22.2
CVE-2004-1446

Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

Dec 31, 2004 106 affected product(s) NVD
5.0
CVSS
3.1%
EPSS
⚡ 20.9
CVE-2004-1470

CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
2.4%
EPSS
⚡ 20.7
CVE-2004-1425

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

Dec 31, 2004 10 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5