Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1210 HTML Injection vulnerability in Ipcop 1.4.1
Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.
network
ipcop
6.8
2005-01-10 CVE-2004-1209 Remote Security vulnerability in Payflow Link
Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.
network
low complexity
verisign
5.0
2005-01-10 CVE-2004-1208 Remote Buffer Overflow vulnerability in 21-6 Productions Orbz
Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.
network
low complexity
21-6-productions
critical
10.0
2005-01-10 CVE-2004-1207 Remote Denial Of Service vulnerability in SeriousSam SeriousEngine User Management
The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.
network
low complexity
serioussam
5.0
2005-01-10 CVE-2004-1206 Directory Traversal vulnerability in PNTresMailer
Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a ..
network
low complexity
pntresmailer
5.0
2005-01-10 CVE-2004-1205 codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.
network
low complexity
pntresmailer
5.0
2005-01-10 CVE-2004-1204 Denial-Of-Service vulnerability in Fluxbot
FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.
local
low complexity
fluxbox-team
2.1
2005-01-10 CVE-2004-1203 Information Disclosure vulnerability in PHPcms 1.1.9/1.2.0/1.2.1
parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.
network
low complexity
phpcms
5.0
2005-01-10 CVE-2004-1202 Cross-Site Scripting vulnerability in PHPcms 1.1.9/1.2/1.2.1
Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
network
phpcms
6.8
2005-01-10 CVE-2004-1201 Resource Exhaustion vulnerability in Opera Browser
Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
network
low complexity
opera CWE-400
5.0