CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2003-1010

    Last Modified: 16 Apr 2026

    Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.

    Published: 10 Mar 2004
    7.2
    High

    CVE-2003-1011

    Last Modified: 16 Apr 2026

    Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes the init process and leaves the user in a root shell.

    Published: 10 Mar 2004
    7.2
    High

    CVE-2003-1018

    Last Modified: 16 Apr 2026

    Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2004-0158

    Last Modified: 16 Apr 2026

    Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.

    Published: 10 Mar 2004
    10
    Critical

    CVE-2003-0170

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

    Published: 10 Mar 2004
    5
    Medium

    CVE-2003-0797

    Last Modified: 16 Apr 2026

    Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2003-0828

    Last Modified: 16 Apr 2026

    Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.

    Published: 10 Mar 2004
    7.2
    High

    CVE-2003-1006

    Last Modified: 16 Apr 2026

    Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.

    Published: 10 Mar 2004
    5
    Medium

    CVE-2003-1007

    Last Modified: 16 Apr 2026

    AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2003-1008

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.

    Published: 10 Mar 2004
    10
    Critical

    CVE-2003-1009

    Last Modified: 16 Apr 2026

    Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.

    Published: 10 Mar 2004
    7.5
    High

    CVE-2003-0592

    Last Modified: 16 Apr 2026

    Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2004-0107

    Last Modified: 16 Apr 2026

    The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.

    Published: 10 Mar 2004
    7.5
    High

    CVE-2003-0594

    Last Modified: 16 Apr 2026

    Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2004-0108

    Last Modified: 16 Apr 2026

    The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.

    Published: 10 Mar 2004
    5
    Medium

    CVE-2004-0111

    Last Modified: 16 Apr 2026

    gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.

    Published: 10 Mar 2004
    7.2
    High

    CVE-2004-0148

    Last Modified: 16 Apr 2026

    wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.

    Published: 8 Mar 2004
    10
    Critical

    CVE-2004-0185

    Last Modified: 16 Apr 2026

    Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) request with a long name.

    Published: 8 Mar 2004
    Unknown

    CVE-2004-0187

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0185. Reason: This candidate is a reservation duplicate of CVE-2004-0185. Notes: All CVE users should reference CVE-2004-0185 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Mar 2004
    6.8
    Medium

    CVE-2004-0192

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

    Published: 4 Mar 2004
    10
    Critical

    CVE-2004-0168

    Last Modified: 16 Apr 2026

    Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

    Published: 4 Mar 2004
    5
    Medium

    CVE-2004-0166

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."

    Published: 4 Mar 2004
    4.6
    Medium

    CVE-2004-1359

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.

    Published: 4 Mar 2004
    5
    Medium

    CVE-2004-0176

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

    Published: 4 Mar 2004
    4.6
    Medium

    CVE-2004-0114

    Last Modified: 16 Apr 2026

    The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.

    Published: 3 Mar 2004
    10
    Critical

    CVE-2004-0040

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.

    Published: 3 Mar 2004
    4.6
    Medium

    CVE-2004-0115

    Last Modified: 16 Apr 2026

    VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.

    Published: 3 Mar 2004
    5
    Medium

    CVE-2004-0131

    Last Modified: 16 Apr 2026

    The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.

    Published: 3 Mar 2004
    9.3
    Critical

    CVE-2003-0825

    Last Modified: 16 Apr 2026

    The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 3 Mar 2004
    4.6
    Medium

    CVE-2004-0089

    Last Modified: 16 Apr 2026

    Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.

    Published: 3 Mar 2004
    5
    Medium

    CVE-2004-1990

    Last Modified: 16 Apr 2026

    Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.

    Published: 3 Mar 2004
    4.6
    Medium

    CVE-2004-0099

    Last Modified: 16 Apr 2026

    mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access restrictions.

    Published: 3 Mar 2004
    7.5
    High

    CVE-2004-0128

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.

    Published: 3 Mar 2004
    7.5
    High

    CVE-2004-0009

    Last Modified: 16 Apr 2026

    Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

    Published: 3 Mar 2004
    5
    Medium

    CVE-2004-0129

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.

    Published: 3 Mar 2004
    2.6
    Low

    CVE-2005-0664

    Last Modified: 16 Apr 2026

    Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.

    Published: 3 Mar 2004
    7.5
    High

    CVE-2004-0189

    Last Modified: 16 Apr 2026

    The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.

    Published: 29 Feb 2004
    5
    Medium

    CVE-2004-0944

    Last Modified: 16 Apr 2026

    The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.

    Published: 28 Feb 2004
    5
    Medium

    CVE-2004-0177

    Last Modified: 16 Apr 2026

    The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.

    Published: 28 Feb 2004
    2.1
    Low

    CVE-2004-0181

    Last Modified: 16 Apr 2026

    The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.

    Published: 28 Feb 2004
    2.1
    Low

    CVE-2004-1360

    Last Modified: 16 Apr 2026

    Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.

    Published: 27 Feb 2004
    2.1
    Low

    CVE-2009-0754

    Last Modified: 23 Apr 2026

    PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

    Published: 27 Feb 2004
    4.6
    Medium

    CVE-2004-0906

    Last Modified: 16 Apr 2026

    The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.

    Published: 26 Feb 2004
    6.8
    Medium

    CVE-2004-0191

    Last Modified: 16 Apr 2026

    Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.

    Published: 25 Feb 2004
    7.2
    High

    CVE-2004-0172

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.

    Published: 23 Feb 2004
    4.3
    Medium

    CVE-2004-0322

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.

    Published: 23 Feb 2004
    7.5
    High

    CVE-2004-0324

    Last Modified: 16 Apr 2026

    Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.

    Published: 23 Feb 2004
    5
    Medium

    CVE-2004-0466

    Last Modified: 16 Apr 2026

    WebConnect 6.5, 6.4.4, and possibly earlier versions allows remote attackers to cause a denial of service (hang) via a URL containing an MS-DOS device name such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.

    Published: 21 Feb 2004
    5
    Medium

    CVE-2004-0113

    Last Modified: 16 Apr 2026

    Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.

    Published: 20 Feb 2004
    7.2
    High

    CVE-2003-0441

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.

    Published: 19 Feb 2004