CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-3273

    Last Modified: 16 Apr 2026

    The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bounds errors with a large number of digipeats.

    Published: 16 Dec 2004
    10
    Critical

    CVE-2004-1154

    Last Modified: 16 Apr 2026

    Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.

    Published: 16 Dec 2004
    7.5
    High

    CVE-2004-1321

    Last Modified: 16 Apr 2026

    The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1233

    Last Modified: 16 Apr 2026

    Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1225

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.

    Published: 15 Dec 2004
    4.6
    Medium

    CVE-2004-1224

    Last Modified: 16 Apr 2026

    Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.

    Published: 15 Dec 2004
    6.8
    Medium

    CVE-2004-1196

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1226

    Last Modified: 16 Apr 2026

    SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-0568

    Last Modified: 16 Apr 2026

    HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-0571

    Last Modified: 16 Apr 2026

    Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.

    Published: 15 Dec 2004
    7.2
    High

    CVE-2004-0894

    Last Modified: 16 Apr 2026

    LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1022

    Last Modified: 16 Apr 2026

    Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1023

    Last Modified: 16 Apr 2026

    Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1145

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.

    Published: 15 Dec 2004
    6.8
    Medium

    CVE-2004-1197

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in inshop.pl in Insite inShop allows remote attackers to inject arbitrary web script or HTML via the screen parameter.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1198

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1199

    Last Modified: 16 Apr 2026

    Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1205

    Last Modified: 16 Apr 2026

    codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1206

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1207

    Last Modified: 16 Apr 2026

    The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1208

    Last Modified: 16 Apr 2026

    Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1211

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1216

    Last Modified: 16 Apr 2026

    The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1217

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1219

    Last Modified: 16 Apr 2026

    paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1227

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1319

    Last Modified: 16 Apr 2026

    The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.

    Published: 15 Dec 2004
    7.5
    High

    CVE-2004-1322

    Last Modified: 16 Apr 2026

    Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.

    Published: 15 Dec 2004
    7.5
    High

    CVE-2004-1320

    Last Modified: 16 Apr 2026

    Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1334

    Last Modified: 16 Apr 2026

    Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1333

    Last Modified: 16 Apr 2026

    Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-0899

    Last Modified: 16 Apr 2026

    The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-0900

    Last Modified: 16 Apr 2026

    The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1147

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1148

    Last Modified: 16 Apr 2026

    phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.

    Published: 15 Dec 2004
    7.5
    High

    CVE-2004-1173

    Last Modified: 16 Apr 2026

    Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog.

    Published: 15 Dec 2004
    1.2
    Low

    CVE-2004-1191

    Last Modified: 16 Apr 2026

    Race condition in SuSE Linux 8.1 through 9.2, when run on SMP systems that have more than 4GB of memory, could allow local users to read unauthorized memory from "foreign memory pages."

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1200

    Last Modified: 16 Apr 2026

    Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1201

    Last Modified: 16 Apr 2026

    Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

    Published: 15 Dec 2004
    6.8
    Medium

    CVE-2004-1202

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1203

    Last Modified: 16 Apr 2026

    parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1209

    Last Modified: 16 Apr 2026

    Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

    Published: 15 Dec 2004
    6.8
    Medium

    CVE-2004-1210

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1212

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.

    Published: 15 Dec 2004
    6.8
    Medium

    CVE-2004-1213

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1214

    Last Modified: 16 Apr 2026

    Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1218

    Last Modified: 16 Apr 2026

    Remote Execute 2.30 allows remote attackers to cause a denial of service (application crash) by making 7 simultaneous connections.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1221

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1222

    Last Modified: 16 Apr 2026

    weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1223

    Last Modified: 16 Apr 2026

    The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.

    Published: 15 Dec 2004