7.2
    High

    CVE-2004-0186

    Last Modified: 2 Dec 2016

    smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

    Source:Martin Fiala
    Published:15 Mar 2004
    5
    Medium

    CVE-2004-0184

    Last Modified: 16 Mar 2016

    Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Source:Rapid7
    Published:29 Mar 2004
    6.8
    Medium

    CVE-2004-0179

    Last Modified: 9 Jan 2013

    Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

    Source:Thomas Wana
    Published:14 Apr 2004
    5
    Medium

    CVE-2004-0176

    Last Modified: 5 Dec 2016

    Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

    Source:Abhisek Datta
    Published:4 Mar 2004
    5
    Medium

    CVE-2004-0173

    Last Modified: 30 Dec 2012

    Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

    Source:Jeremy Bae
    Published:15 Apr 2004
    5
    Medium

    CVE-2004-0164

    Last Modified: 20 Dec 2012

    KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.

    Source:Thomas Walpuski
    Published:13 Jan 2004
    7.5
    High

    CVE-2004-0159

    Last Modified: 22 Nov 2017

    Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

    Published:15 Mar 2004
    4.6
    Medium

    CVE-2004-0158

    Last Modified: 13 Apr 2017

    Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.

    Source:Li0n7
    Published:10 Mar 2004
    7.5
    High

    CVE-2004-0132

    Last Modified: 26 Dec 2012

    Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.

    Source:Cedric Cochin
    Published:14 Feb 2004
    5
    Medium

    CVE-2004-0129

    Last Modified: 24 Dec 2012

    Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.

    Source:Cedric Cochin
    Published:3 Mar 2004
    7.5
    High

    CVE-2004-0128

    Last Modified: 24 Dec 2012

    PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.

    Source:Cedric Cochin
    Published:3 Mar 2004
    7.5
    High

    CVE-2004-0121

    Last Modified: 1 Jan 2013

    Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

    Source:shaun2k2
    Published:15 Apr 2004
    5
    Medium

    CVE-2004-0120

    Last Modified: 16 Apr 2026

    The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.

    Source:David Barroso
    Published:16 Apr 2004
    4.6
    Medium

    CVE-2004-0114

    Last Modified: 31 Dec 2012

    The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.

    Source:Joost Pol
    Published:3 Mar 2004
    7.5
    High

    CVE-2004-0110

    Last Modified: 12 Apr 2016

    Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.

    Source:infamous41md
    Published:12 Feb 2004
    7.5
    High

    CVE-2004-0104

    Last Modified: 31 Dec 2012

    Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

    Source:Ulf Harnhammar
    Published:18 Feb 2004
    5
    Medium

    CVE-2004-0095

    Last Modified: 23 Dec 2012

    McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.

    Source:cyber_flash
    Published:17 Feb 2004
    10
    Critical

    CVE-2004-0084

    Last Modified: 27 Dec 2012

    Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

    Source:Greg MacManus
    Published:12 Feb 2004
    10
    Critical

    CVE-2004-0083

    Last Modified: 26 Dec 2012

    Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

    Published:8 Feb 2004
    7.2
    High

    CVE-2004-0077

    Last Modified: 23 Nov 2016

    The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

    Source:Paul Starzetz
    Published:18 Feb 2004
    4.6
    Medium

    CVE-2004-0074

    Last Modified: 19 Dec 2012

    Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.

    Source:N2n-Hacker
    Published:22 Jan 2004
    7.5
    High

    CVE-2004-0073

    Last Modified: 19 Dec 2012

    PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.

    Source:tsbeginnervn
    Published:15 Jan 2004
    5
    Medium

    CVE-2004-0072

    Last Modified: 20 Dec 2012

    Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.

    Source:Mark Bassett
    Published:15 Jan 2004
    5
    Medium

    CVE-2004-0071

    Last Modified: 20 Dec 2012

    Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.

    Source:Cabezon Aurelien
    Published:15 Jan 2004
    7.5
    High

    CVE-2004-0070

    Last Modified: 20 Dec 2012

    PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

    Source:Zero X
    Published:17 Feb 2004
    7.5
    High

    CVE-2004-0069

    Last Modified: 20 Dec 2012

    Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

    Source:mandragore
    Published:15 Jan 2004
    4.3
    Medium

    CVE-2004-0067

    Last Modified: 18 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

    Source:JeiAr
    Published:15 Jan 2004
    2.1
    Low

    CVE-2004-0064

    Last Modified: 22 Nov 2017

    The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.

    Source:l0om
    Published:15 Jan 2004
    4.3
    Medium

    CVE-2004-0046

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.

    Source:Rafel Ivgi
    Published:14 Jan 2004
    5
    Medium

    CVE-2004-0033

    Last Modified: 20 Dec 2012

    admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

    Source:Windak
    Published:20 Jan 2004
    6.8
    Medium

    CVE-2004-0032

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.

    Source:Windak
    Published:20 Jan 2004
    9.8
    Critical

    CVE-2004-0030

    Last Modified: 20 Dec 2012

    PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

    Source:Windak
    Published:8 Jan 2004
    5.6
    Medium

    CVE-2003-20001

    Last Modified: 2 Apr 2025

    An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.

    Source:Andrea Intilangelo
    Published:1 Apr 2025
    5
    Medium

    CVE-2003-1571

    Last Modified: 5 Jan 2017

    Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.

    Source:Cold Zero
    Published:2 Apr 2009
    5
    Medium

    CVE-2003-1566

    Last Modified: 18 Dec 2012

    Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

    Source:Parcifal Aertssen
    Published:15 Jan 2009
    5
    Medium

    CVE-2003-1555

    Last Modified: 3 Nov 2012

    ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.

    Source:euronymous
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1553

    Last Modified: 31 Oct 2012

    Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

    Source:dwcgr0up
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1550

    Last Modified: 1 Nov 2012

    XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.

    Source:gregory Le Bras
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1548

    Last Modified: 31 Oct 2012

    MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.

    Source:gregory Le Bras
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1545

    Last Modified: 2 Nov 2012

    Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

    Source:Zero-X www.lobnan.de Team
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1541

    Last Modified: 2 Nov 2012

    PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.

    Source:subj
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1540

    Last Modified: 1 Nov 2012

    WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

    Source:subj
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1536

    Last Modified: 1 Nov 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

    Source:Ertan Kurt
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1535

    Last Modified: 3 Nov 2012

    Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

    Source:euronymous
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1533

    Last Modified: 21 Oct 2012

    SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

    Source:frog
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1532

    Last Modified: 24 Oct 2012

    SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

    Source:frog
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1530

    Last Modified: 23 Oct 2012

    SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

    Source:Ulf Harnhammar
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1522

    Last Modified: 9 Dec 2012

    Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.

    Source:SecuriTeam
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1521

    Last Modified: 9 Dec 2012

    Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

    Source:Marc Schoenefeld
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1520

    Last Modified: 9 Dec 2012

    SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Source:Ezhilan
    Published:31 Dec 2003