Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2013 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.
local
low complexity
linux CWE-190
7.8
2004-12-31 CVE-2004-1995 Cross-Site Request Forgery (CSRF) vulnerability in Fusetalk 2.0
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
network
low complexity
fusetalk CWE-352
6.5
2004-12-31 CVE-2004-1901 Link Following vulnerability in Gentoo Linux and Portage
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
local
low complexity
gentoo CWE-59
5.5
2004-12-31 CVE-2004-1842 Cross-Site Request Forgery (CSRF) vulnerability in PHPnuke PHP-Nuke
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
network
low complexity
phpnuke CWE-352
8.8
2004-12-31 CVE-2004-1464 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
network
high complexity
cisco
5.9
2004-12-23 CVE-2004-0816 Integer Underflow (Wrap or Wraparound) vulnerability in Linux Kernel
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.
network
low complexity
linux CWE-191
7.5
2004-12-03 CVE-2004-1083 Improper Handling of Case Sensitivity vulnerability in Apple products
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
network
low complexity
apple CWE-178
7.5
2004-11-23 CVE-2004-0346 Off-by-one Error vulnerability in Proftpd 1.2.7/1.2.8/1.2.9
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.
local
low complexity
proftpd CWE-193
7.8
2004-11-23 CVE-2004-0342 Off-by-one Error vulnerability in Wftpd PRO Server Project Wftpd PRO Server 3.21
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
local
low complexity
wftpd-pro-server-project CWE-193
5.5
2004-11-23 CVE-2004-0285 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
9.8