Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-2542 | Undisclosed SQL Injection vulnerability in Dynix WebPac Multiple SQL injection vulnerabilities in Dynix (formerly known as epixtech) WebPAC allow remote attackers to execute arbitrary SQL commands via unknown attack vectors, resulting in an ability to execute stored procedures, bypass login authentication, and cause an unspecified denial of service to backend databases. | 7.5 |
2004-12-31 | CVE-2004-2541 | Buffer Errors vulnerability in Cscope 15.5 Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target. | 6.9 |
2004-12-31 | CVE-2004-2540 | Denial-Of-Service vulnerability in SUN JDK and JRE readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data. | 5.0 |
2004-12-31 | CVE-2004-2539 | Remote Undisclosed Denial Of Service vulnerability in Network Appliance Data Ontap and Netcache Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID | 7.8 |
2004-12-31 | CVE-2004-2538 | Unspecified vulnerability in Nilesh Dosooye PHPcodegenie Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer. | 6.5 |
2004-12-31 | CVE-2004-2537 | Unspecified vulnerability in NetWin SurgeMail Webmail Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | 10.0 |
2004-12-31 | CVE-2004-2536 | Local IO Access Inheritance vulnerability in Linux Kernel The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other processes to access the per-TSS pointers, access restricted memory locations, and possibly gain privileges. | 7.5 |
2004-12-31 | CVE-2004-2535 | Unspecified vulnerability in Matthew Phillips Sticker 3.0.0 The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key. | 5.0 |
2004-12-31 | CVE-2004-2534 | Denial Of Service vulnerability in Fastream NetFile FTP/Web Server HEAD Request Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests. | 7.8 |
2004-12-31 | CVE-2004-2533 | Improper Input Validation vulnerability in Solarwinds Serv-U File Server 4.1.0.0 Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111. | 5.0 |