Show filters
250 Total Results
Displaying 211-220 of 250
Sort by:
Attacker Value
Unknown
CVE-2004-1319
Disclosure Date: December 15, 2004 (last updated February 22, 2025)
The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.
0
Attacker Value
Unknown
CVE-2003-1208
Disclosure Date: December 03, 2004 (last updated February 22, 2025)
Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
0
Attacker Value
Unknown
CVE-2004-0301
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2004-0300
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.
0
Attacker Value
Unknown
CVE-2004-0637
Disclosure Date: September 02, 2004 (last updated February 22, 2025)
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
0
Attacker Value
Unknown
CVE-2004-1774
Disclosure Date: August 31, 2004 (last updated February 22, 2025)
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.
0
Attacker Value
Unknown
CVE-2004-0839
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
0
Attacker Value
Unknown
CVE-2004-0202
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
0
Attacker Value
Unknown
CVE-2004-0201
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
0
Attacker Value
Unknown
CVE-2004-1371
Disclosure Date: August 04, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
0