Show filters
205 Total Results
Displaying 161-170 of 205
Sort by:
Attacker Value
Unknown

CVE-2004-0749

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
0
Attacker Value
Unknown

CVE-2004-0834

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.
0
Attacker Value
Unknown

CVE-2004-0604

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
0
Attacker Value
Unknown

CVE-2004-0456

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.
0
Attacker Value
Unknown

CVE-2004-0608

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.
0
Attacker Value
Unknown

CVE-2004-0333

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
0
Attacker Value
Unknown

CVE-2004-0746

Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown

CVE-2004-1613

Disclosure Date: October 18, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
0
Attacker Value
Unknown

CVE-2004-0500

Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
0
Attacker Value
Unknown

CVE-2004-0458

Disclosure Date: September 28, 2004 (last updated February 22, 2025)
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.