Show filters
417 Total Results
Displaying 321-330 of 417
Sort by:
Attacker Value
Unknown

CVE-2004-1023

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.
0
Attacker Value
Unknown

CVE-2004-1022

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
0
Attacker Value
Unknown

CVE-2004-2679

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
0
Attacker Value
Unknown

CVE-2004-1472

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.
0
Attacker Value
Unknown

CVE-2004-1474

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.
0
Attacker Value
Unknown

CVE-2004-1473

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.
0
Attacker Value
Unknown

CVE-2004-0369

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.
0
Attacker Value
Unknown

CVE-2004-2395

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
0
Attacker Value
Unknown

CVE-2004-2394

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
0
Attacker Value
Unknown

CVE-2004-0834

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.
0