Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-02-09 CVE-2004-0964 Remote Buffer Overflow vulnerability in Zinf Malformed Playlist File
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
network
low complexity
zinf debian
critical
10.0
2005-02-09 CVE-2004-0963 Unspecified vulnerability in Microsoft Word 2002
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
network
low complexity
microsoft
critical
10.0
2005-02-09 CVE-2004-0962 Unspecified vulnerability in Apple Remote Desktop 2.0.0
Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.
network
low complexity
apple
critical
10.0
2005-02-09 CVE-2004-0961 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
network
low complexity
freeradius redhat
5.0
2005-02-09 CVE-2004-0960 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
network
low complexity
freeradius redhat
5.0
2005-02-09 CVE-2004-0957 Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities. 6.8
2005-02-09 CVE-2004-0950 Information Disclosure vulnerability in Danware NetOp Remote Control
NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.
network
low complexity
danware-data
5.0
2005-02-09 CVE-2004-0947 Remote Buffer Overflow vulnerability in ARJ Software UNARJ
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
network
low complexity
arj-software-inc gentoo suse
critical
10.0
2005-02-09 CVE-2004-0941 Remote Buffer overflow vulnerability in GD Graphics Library
Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.
network
low complexity
gd-graphics-library trustix
critical
10.0
2005-02-09 CVE-2004-0940 Incorrect Calculation of Buffer Size vulnerability in multiple products
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
local
low complexity
openpkg apache slackware hp suse trustix CWE-131
7.8