Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux HIGH 7.5
CVE-2004-1096EPSS 17%

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 7.5
CVE-2004-1161EPSS 7%

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access re…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 7.5
CVE-2004-1162

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass …

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 7.2
CVE-2004-1115

The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, whi…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 7.2
CVE-2004-1116

The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows loca…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 7.2
CVE-2004-1117

The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by mod…

Patch available
Fix from $1,950 2005-01-10
Linux MEDIUM 6.8
CVE-2004-1106

Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specia…

Patch available
Fix from $1,600 2005-01-10
Mirrorselect MEDIUM 5.0
CVE-2004-1167

mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite…

Patch available
Fix from $1,600 2005-01-10
Linux HIGH 7.2
CVE-2004-1452

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privile…

Patch available
Fix from $1,950 2004-12-31
Linux MEDIUM 5.5
CVE-2004-1901

Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

Fix: 2.0.50+
Fix from $1,600 2004-12-31
Linux MEDIUM 5.0
CVE-2004-1491EPSS 13%

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or la…

Fix: after 7.54
Fix from $1,600 2004-12-31
Linux HIGH 7.2
CVE-2004-0834

Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) …

Mitigation only
Fix from $1,950 2004-12-23
Linux MEDIUM 5.0
CVE-2004-0749

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow rem…

Patch available
Fix from $1,600 2004-12-23
Linux HIGH 10.0
CVE-2004-0608EPSS 74%

The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earl…

Patch available
Fix from $1,950 2004-12-06
Linux HIGH 7.2
CVE-2004-0496

Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities…

Mitigation only
Fix from $1,950 2004-12-06
Linux MEDIUM 5.0
CVE-2004-0604

The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty se…

Patch available
Fix from $1,600 2004-12-06
Linux MEDIUM 5.0
CVE-2004-0633EPSS 18%

The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.

Patch available
Fix from $1,600 2004-12-06
Linux MEDIUM 5.0
CVE-2004-0634EPSS 5%

The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle withou…

Patch available
Fix from $1,600 2004-12-06
Linux MEDIUM 5.0
CVE-2004-0635EPSS 5%

The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) …

Patch available
Fix from $1,600 2004-12-06
Linux HIGH 10.0
CVE-2004-0333EPSS 24%

Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execu…

Patch available
Fix from $1,950 2004-11-23
Linux HIGH 7.5
CVE-2004-0746

Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, whi…

Patch available
Fix from $1,950 2004-10-20
Linux HIGH 7.5
CVE-2004-0500

Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and …

Patch available
Fix from $1,950 2004-09-28
Linux HIGH 10.0
CVE-2004-0226

Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

Patch available
Fix from $1,950 2004-08-18
Linux HIGH 7.5
CVE-2004-0419

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in …

Patch available
Fix from $1,950 2004-08-18
Linux HIGH 7.5
CVE-2004-0432EPSS 9%

ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass inten…

Patch available
Fix from $1,950 2004-08-18
Linux MEDIUM 5.0
CVE-2004-0232

Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary …

Mitigation only
Fix from $1,600 2004-08-18
Linux HIGH 7.5
CVE-2004-1737

SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via…

Patch available
Fix from $1,950 2004-08-16
Linux HIGH 10.0
CVE-2004-0414

CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being …

Patch available
Fix from $1,950 2004-08-06
Linux HIGH 10.0
CVE-2004-0416EPSS 13%

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to exec…

Patch available
Fix from $1,950 2004-08-06
Linux HIGH 10.0
CVE-2004-0418EPSS 6%

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to…

Patch available
Fix from $1,950 2004-08-06