Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2504 Local Privilege Escalation vulnerability in Alt-N MDaemon
The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.
local
low complexity
alt-n
7.2
2004-12-31 CVE-2004-2503 Remote Denial Of Service vulnerability in Inweb Mail Server 2.40
INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.
network
low complexity
inweb
5.0
2004-12-31 CVE-2004-2502 Symbolic Link vulnerability in IM-Switch Insecure Temporary File Handling
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.
local
low complexity
im-switch
2.1
2004-12-31 CVE-2004-2501 Remote Pre-Authentication Buffer Overflow vulnerability in MailEnable IMAP Service
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.
network
low complexity
mailenable
7.5
2004-12-31 CVE-2004-2500 Unspecified vulnerability in IlohaMail
Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.
network
low complexity
ilohamail
critical
10.0
2004-12-31 CVE-2004-2499 Denial Of Service vulnerability in Hitachi Web Page Generator
Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."
network
low complexity
hitachi
7.8
2004-12-31 CVE-2004-2498 Cross-Site Scripting and Information Disclosure vulnerability in Hitachi Web Page Generator
Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.
network
low complexity
hitachi
5.0
2004-12-31 CVE-2004-2497 Cross-Site Scripting and Information Disclosure vulnerability in Hitachi Web Page Generator
Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
network
hitachi
4.3
2004-12-31 CVE-2004-2496 Remote Denial Of Service vulnerability in OpenText FirstClass HTTP Daemon Search Function
The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.
network
low complexity
opentext
7.8
2004-12-31 CVE-2004-2495 Multiple vulnerability in Code-Crafters Ability Mail Server 1.18
The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.
network
low complexity
code-crafters
7.8