Show filters
250 Total Results
Displaying 201-210 of 250
Sort by:
Attacker Value
Unknown
CVE-2004-1547
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2004-2616
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.
0
Attacker Value
Unknown
CVE-2004-2129
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2004-2244
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
0
Attacker Value
Unknown
CVE-2004-0638
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.
0
Attacker Value
Unknown
CVE-2004-1549
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.
0
Attacker Value
Unknown
CVE-2004-1306
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
0
Attacker Value
Unknown
CVE-2004-1548
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.
0
Attacker Value
Unknown
CVE-2004-1361
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2004-1305
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.
0