Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-03-01 CVE-2004-1007 The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
network
low complexity
bogofilter ubuntu
5.0
2005-03-01 CVE-2004-1006 Remote Format String vulnerability in ISC DHCPD
Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, a different vulnerability than CVE-2002-0702.
network
low complexity
isc
critical
10.0
2005-03-01 CVE-2004-1003 Unspecified vulnerability in Trend Micro Scanmail Domino 2.51/2.6
Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.
network
low complexity
trend-micro
5.0
2005-03-01 CVE-2004-1002 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.
network
low complexity
samba canonical CWE-191
7.5
2005-03-01 CVE-2004-1001 Unspecified vulnerability in Debian Shadow 4.0.4.1
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.
local
low complexity
debian
4.6
2005-03-01 CVE-2004-0992 Remote Format String vulnerability in Proxytunnel
Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.
network
low complexity
proxytunnel
critical
10.0
2005-03-01 CVE-2004-0990 Remote Integer Overflow vulnerability in GD Graphics Library
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
network
low complexity
gd-graphics-library openpkg gentoo suse trustix
critical
10.0
2005-03-01 CVE-2004-0989 Remote Stack Buffer Overflow vulnerability in Libxml2
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
network
low complexity
xmlsoft xmlstarlet redhat trustix ubuntu
critical
10.0
2005-03-01 CVE-2004-0988 Unspecified vulnerability in Apple Quicktime
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.
network
low complexity
apple
5.0
2005-03-01 CVE-2004-0986 Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
network
low complexity
suse debian linux redhat
7.5