Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1187 Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2005-01-10 CVE-2004-1177 Unspecified vulnerability in GNU Mailman
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
network
gnu
4.3
2005-01-10 CVE-2004-1172 Remote Buffer Overflow vulnerability in VERITAS Backup Exec Agent Browser
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.
network
low complexity
symantec-veritas
critical
10.0
2005-01-10 CVE-2004-1171 KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.
local
low complexity
kde mandrakesoft redhat
2.1
2005-01-10 CVE-2004-1170 a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
network
low complexity
gnu sun suse
critical
10.0
2005-01-10 CVE-2004-1169 Denial-Of-Service vulnerability in MaxDB
MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.
network
low complexity
mysql
5.0
2005-01-10 CVE-2004-1168 Remote Security vulnerability in MaxDB
Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a long Overwrite header.
network
low complexity
mysql
critical
10.0
2005-01-10 CVE-2004-1167 Remote Security vulnerability in mirrorselect
mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.
network
low complexity
gentoo
5.0
2005-01-10 CVE-2004-1165 Unspecified vulnerability in KDE Kdelibs and Konqueror
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
network
low complexity
kde
7.5
2005-01-10 CVE-2004-1164 Remote Denial of Service vulnerability in Cisco CNS Network Registrar DNS and DHCP Server
The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence."
network
low complexity
cisco
5.0