Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-2529 | Remote vulnerability in Gadu-Gadu Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities. | 5.0 |
2004-12-31 | CVE-2004-2528 | Cross-Site Scripting vulnerability in Webcam Corp Webcam Watchdog 4.0.1A Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter. network webcam-corp | 4.3 |
2004-12-31 | CVE-2004-2527 | The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running. | 5.4 |
2004-12-31 | CVE-2004-2526 | Directory Traversal vulnerability in IBM Tivoli Directory Server LDACGI Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. | 5.0 |
2004-12-31 | CVE-2004-2525 | Remote Cross-Site Scripting vulnerability in S9Y Serendipity Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable. network s9y | 4.3 |
2004-12-31 | CVE-2004-2524 | Information Disclosure vulnerability in WHM Autopilot WHM Autopilot 2.4.5 clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form. | 5.0 |
2004-12-31 | CVE-2004-2523 | Remote Message Format String vulnerability in Openftpd FTP Server 0.29.4/0.30/0.30.1 Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument. | 6.5 |
2004-12-31 | CVE-2004-2517 | Denial-Of-Service vulnerability in Myserver 0.7.1 myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | 5.0 |
2004-12-31 | CVE-2004-2516 | Directory Traversal vulnerability in MyServer Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences. | 5.0 |
2004-12-31 | CVE-2004-2515 | Local Format String vulnerability in VMWare Workstation 4.5.2Build8848 Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. | 7.2 |