Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1164 Remote Denial of Service vulnerability in Cisco CNS Network Registrar DNS and DHCP Server
The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence."
network
low complexity
cisco
5.0
2005-01-10 CVE-2004-1163 Denial-Of-Service vulnerability in CNS Network Registrar
Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets.
network
low complexity
cisco
5.0
2005-01-10 CVE-2004-1162 Remote Arbitrary Command Execution vulnerability in SCPOnly
The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.
network
low complexity
scponly gentoo
7.5
2005-01-10 CVE-2004-1161 Remote Arbitrary Command Execution vulnerability in RSSH
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
network
low complexity
rssh gentoo
7.5
2005-01-10 CVE-2004-1160 Remote Window Hijacking vulnerability in Netscape
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
netscape
7.5
2005-01-10 CVE-2004-1158 Remote Window Hijacking vulnerability in KDE Konqueror
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
kde mandrakesoft redhat
7.5
2005-01-10 CVE-2004-1157 Injection vulnerability in Opera Browser
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
opera CWE-74
7.5
2005-01-10 CVE-2004-1154 Remote Integer Overflow vulnerability in Samba Directory Access Control List
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
network
low complexity
samba redhat suse trustix
critical
10.0
2005-01-10 CVE-2004-1153 Denial-Of-Service vulnerability in Adobe Acrobat Reader 6.0/6.0.2/8.0
Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.
network
low complexity
adobe
critical
10.0
2005-01-10 CVE-2004-1152 Unspecified vulnerability in Adobe Acrobat Reader 5.0.9
Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.
network
low complexity
adobe
critical
10.0