Show filters
250 Total Results
Displaying 201-210 of 250
Sort by:
Attacker Value
Unknown

CVE-2004-1547

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2004-2616

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.
0
Attacker Value
Unknown

CVE-2004-2129

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2004-2244

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
0
Attacker Value
Unknown

CVE-2004-0638

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.
0
Attacker Value
Unknown

CVE-2004-1549

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.
0
Attacker Value
Unknown

CVE-2004-1306

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
0
Attacker Value
Unknown

CVE-2004-1548

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.
0
Attacker Value
Unknown

CVE-2004-1361

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2004-1305

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.
0