Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2651 Cross-Site Scripting vulnerability in YACY Peer-To-Peer Search Engine
Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.
4.3
2004-12-31 CVE-2004-2650 Denial Of Service vulnerability in Apache James 2.2.0
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
local
low complexity
apache
4.9
2004-12-31 CVE-2004-2649 Improper Input Validation vulnerability in Eudora 6.1.0.6
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g.
network
eudora CWE-20
5.8
2004-12-31 CVE-2004-2648 Denial-Of-Service vulnerability in FreezeX
FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.
local
high complexity
faronics
1.0
2004-12-31 CVE-2004-2647 Denial Of Service vulnerability in Multiple Free Web Chat
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.
network
low complexity
reid-garner
5.0
2004-12-31 CVE-2004-2646 Denial Of Service vulnerability in Multiple Free Web Chat
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.
network
low complexity
reid-garner
5.0
2004-12-31 CVE-2004-2645 Multiple Unspecified vulnerability in Asn.1 Compiler Asn.1 Compiler 0.9.4/0.9.5/0.9.6
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."
network
low complexity
asn-1-compiler
critical
10.0
2004-12-31 CVE-2004-2644 Multiple Unspecified vulnerability in Asn.1 Compiler Asn.1 Compiler 0.9.4/0.9.5/0.9.6
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.
network
low complexity
asn-1-compiler
critical
10.0
2004-12-31 CVE-2004-2643 Directory Traversal vulnerability in Microsoft CABARC
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.
local
high complexity
microsoft
3.7
2004-12-31 CVE-2004-2642 Unspecified vulnerability in Nathaniel Bray Yeemp
Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.
network
low complexity
nathaniel-bray
6.4