Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-01-27 CVE-2004-0917 Remote Information Disclosure vulnerability in Vignette Application Portal
The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.
network
low complexity
vignette
5.0
2005-01-27 CVE-2004-0916 Unspecified vulnerability in Cabextract Project Cabextract 0.2/0.6/1.0
Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing ..
network
low complexity
cabextract-project
5.0
2005-01-27 CVE-2004-0903 Remote Buffer Overflow vulnerability in Mozilla Browser Vcard Handling
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
network
low complexity
mozilla conectiva redhat suse
critical
10.0
2005-01-27 CVE-2004-0902 Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
network
low complexity
mozilla conectiva redhat suse
critical
10.0
2005-01-27 CVE-2004-0892 Unspecified vulnerability in Microsoft ISA Server, Proxy Server and Windows 2003 Server
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
network
low complexity
microsoft
7.5
2005-01-27 CVE-2004-0891 Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
network
low complexity
rob-flynn gentoo slackware ubuntu
critical
10.0
2005-01-27 CVE-2004-0889 Integer Overflow vulnerability in Xpdf PDFTOPS
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
10.0
2005-01-27 CVE-2004-0888 Integer Overflow vulnerability in Xpdf PDFTOPS
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
10.0
2005-01-27 CVE-2004-0887 Local Privilege Escalation vulnerability in Linux IBM S/390 Kernel SACF Instruction
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.
local
low complexity
linux suse
7.2
2005-01-27 CVE-2004-0886 Buffer Overflow vulnerability in LibTIFF
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
5.0