Show filters
104 Total Results
Displaying 91-100 of 104
Sort by:
Attacker Value
Unknown

CVE-2004-1452

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.
0
Attacker Value
Unknown

CVE-2004-0805

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
0
Attacker Value
Unknown

CVE-2004-0749

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
0
Attacker Value
Unknown

CVE-2004-0333

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
0
Attacker Value
Unknown

CVE-2004-0500

Disclosure Date: September 28, 2004 (last updated February 22, 2025)
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
0
Attacker Value
Unknown

CVE-2004-0232

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0432

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2004-0226

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0231

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
0
Attacker Value
Unknown

CVE-2004-0233

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.
0