Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-10-18 CVE-2004-1603 Link Following vulnerability in Cpanel 9.4.1
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
local
low complexity
cpanel CWE-59
5.5
2004-09-28 CVE-2004-0689 Link Following vulnerability in multiple products
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
local
low complexity
kde debian CWE-59
7.1
2004-09-28 CVE-2004-0458 NULL Pointer Dereference vulnerability in multiple products
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
network
low complexity
nicolas-boullis debian CWE-476
7.5
2004-08-11 CVE-2004-1714 Incorrect Permission Assignment for Critical Resource vulnerability in ISS Blackice PC Protection and Blackice Server Protection
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.
local
low complexity
iss CWE-732
7.1
2004-08-06 CVE-2004-0213 Missing Authentication for Critical Function vulnerability in Microsoft Windows 2000
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.
local
low complexity
microsoft CWE-306
7.8
2004-08-06 CVE-2004-0210 Classic Buffer Overflow vulnerability in Microsoft Interix, Windows 2000 and Windows NT
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
local
low complexity
microsoft CWE-120
7.8
2004-08-04 CVE-2004-1363 Incorrect Calculation of Buffer Size vulnerability in Oracle products
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
network
low complexity
oracle CWE-131
critical
9.8
2004-07-30 CVE-2004-1703 Cross-Site Request Forgery (CSRF) vulnerability in Fusionphp Fusion News 3.6.1
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
network
low complexity
fusionphp CWE-352
8.8
2004-07-27 CVE-2004-2061 Server-Side Request Forgery (SSRF) vulnerability in Risearch and Risearch PRO
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.
network
low complexity
risearch CWE-918
critical
9.8
2004-07-27 CVE-2003-1048 Double Free vulnerability in Microsoft products
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
local
low complexity
microsoft CWE-415
7.8