CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1314

    Last Modified: 16 Apr 2026

    Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

    Published: 22 Dec 2004
    4.6
    Medium

    CVE-2004-1778

    Last Modified: 16 Apr 2026

    Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.

    Published: 22 Dec 2004
    5
    Medium

    CVE-2005-0066

    Last Modified: 16 Apr 2026

    The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka "TCP acknowledgement number checking"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 22 Dec 2004
    5
    Medium

    CVE-2005-0067

    Last Modified: 16 Apr 2026

    The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 22 Dec 2004
    5
    Medium

    CVE-2005-0068

    Last Modified: 16 Apr 2026

    The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2005-0441

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1254

    Last Modified: 16 Apr 2026

    WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1259

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1260

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1266

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_field_headers function in csv2xml.cpp for csv2xml 0.5.1 allows remote attackers to execute arbitrary code via a crafted CSV file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1274

    Last Modified: 16 Apr 2026

    The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1275

    Last Modified: 16 Apr 2026

    Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file.

    Published: 22 Dec 2004
    2.1
    Low

    CVE-2004-1276

    Last Modified: 16 Apr 2026

    IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploaded by creating temporary files with names generated by the tmpnam function, before the files are opened by IglooFTP.

    Published: 22 Dec 2004
    5
    Medium

    CVE-2004-1277

    Last Modified: 16 Apr 2026

    The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1278

    Last Modified: 16 Apr 2026

    Buffer overflow in the switch_voice function in parse.c for jcabc2ps 20040902 allows remote attackers to execute arbitrary code via a crafted ABC file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1279

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_file_list_stdin function in jpegtoavi 1.5 allows remote attackers to execute arbitrary code via a crafted set of JPEG files and filenames.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1273

    Last Modified: 16 Apr 2026

    Buffer overflow in the DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a long filename.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1283

    Last Modified: 16 Apr 2026

    Buffer overflow in the Mesh::type method in mesh.c for the mview program in Mesh Viewer 0.2.2 allows remote attackers to execute arbitrary code via crafted mesh files.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1284

    Last Modified: 16 Apr 2026

    Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1285

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1286

    Last Modified: 16 Apr 2026

    Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1288

    Last Modified: 16 Apr 2026

    Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1292

    Last Modified: 16 Apr 2026

    Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1293

    Last Modified: 16 Apr 2026

    Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.

    Published: 22 Dec 2004
    5
    Medium

    CVE-2004-1294

    Last Modified: 16 Apr 2026

    The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.

    Published: 22 Dec 2004
    2.1
    Low

    CVE-2004-1295

    Last Modified: 16 Apr 2026

    The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid root, does not verify whether the calling user has sufficient permission to disable an interface, which allows local users to cause a denial of service (network service disabled).

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1297

    Last Modified: 16 Apr 2026

    Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbitrary code via a crafted RTF file.

    Published: 22 Dec 2004
    7.5
    High

    CVE-2004-1291

    Last Modified: 16 Apr 2026

    Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1301

    Last Modified: 16 Apr 2026

    Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (XLS) file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1302

    Last Modified: 16 Apr 2026

    The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1303

    Last Modified: 16 Apr 2026

    Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1304

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1310

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.

    Published: 22 Dec 2004
    10
    Critical

    CVE-2004-1311

    Last Modified: 16 Apr 2026

    Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.

    Published: 22 Dec 2004
    7.2
    High

    CVE-2004-1149

    Last Modified: 16 Apr 2026

    Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe.

    Published: 22 Dec 2004
    7.2
    High

    CVE-2004-1144

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.

    Published: 22 Dec 2004
    2.6
    Low

    CVE-2004-0452

    Last Modified: 16 Apr 2026

    Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

    Published: 21 Dec 2004
    7.2
    High

    CVE-2004-1189

    Last Modified: 16 Apr 2026

    The add_to_history function in svr_principal.c in libkadm5srv for MIT Kerberos 5 (krb5) up to 1.3.5, when performing a password change, does not properly track the password policy's history count and the maximum number of keys, which can cause an array index out-of-bounds error and may allow authenticated users to execute arbitrary code via a heap-based buffer overflow.

    Published: 21 Dec 2004
    10
    Critical

    CVE-2004-1308

    Last Modified: 16 Apr 2026

    Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.

    Published: 21 Dec 2004
    9.3
    Critical

    CVE-2004-1125

    Last Modified: 16 Apr 2026

    Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.

    Published: 21 Dec 2004
    7.5
    High

    CVE-2004-1307

    Last Modified: 16 Apr 2026

    Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.

    Published: 21 Dec 2004
    7.5
    High

    CVE-2004-0852

    Last Modified: 16 Apr 2026

    Buffer overflow in htget 0.93 allows remote attackers to execute arbitrary code via a crafted URL.

    Published: 20 Dec 2004
    7.2
    High

    CVE-2004-1326

    Last Modified: 16 Apr 2026

    Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.

    Published: 20 Dec 2004
    7.2
    High

    CVE-2004-1329

    Last Modified: 16 Apr 2026

    Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

    Published: 20 Dec 2004
    7.2
    High

    CVE-2004-1374

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.

    Published: 18 Dec 2004
    5
    Medium

    CVE-2004-1325

    Last Modified: 16 Apr 2026

    The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

    Published: 18 Dec 2004
    2.6
    Low

    CVE-2004-1324

    Last Modified: 16 Apr 2026

    The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.

    Published: 18 Dec 2004
    5
    Medium

    CVE-2004-1768

    Last Modified: 16 Apr 2026

    The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters.

    Published: 17 Dec 2004
    2.1
    Low

    CVE-2005-0003

    Last Modified: 16 Apr 2026

    The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.

    Published: 17 Dec 2004
    2.1
    Low

    CVE-2004-1323

    Last Modified: 16 Apr 2026

    Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.

    Published: 16 Dec 2004