Show filters
417 Total Results
Displaying 321-330 of 417
Sort by:
Attacker Value
Unknown
CVE-2004-1023
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.
0
Attacker Value
Unknown
CVE-2004-1022
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
0
Attacker Value
Unknown
CVE-2004-2679
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
0
Attacker Value
Unknown
CVE-2004-1472
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.
0
Attacker Value
Unknown
CVE-2004-1474
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.
0
Attacker Value
Unknown
CVE-2004-1473
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.
0
Attacker Value
Unknown
CVE-2004-0369
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.
0
Attacker Value
Unknown
CVE-2004-2395
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
0
Attacker Value
Unknown
CVE-2004-2394
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
0
Attacker Value
Unknown
CVE-2004-0834
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.
0