Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2475 HTML Injection vulnerability in Google Toolbar About.HTML
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section.
network
google
4.3
2004-12-31 CVE-2004-2474 SQL Injection vulnerability in PHPnews 1.2.3
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
network
low complexity
phpnews
7.5
2004-12-31 CVE-2004-2473 Link Following vulnerability in Wmfrog 0.1.6
wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
high complexity
wmfrog CWE-59
1.2
2004-12-31 CVE-2004-2472 Remote Denial of Service vulnerability in Agnitum Outpost Firewall 2.1
Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.
network
low complexity
agnitum
5.0
2004-12-31 CVE-2004-2471 Parameter Unspecified SQL Injection vulnerability in JamesOff Quoteengine 1.0/1.1
SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
jamesoff
7.5
2004-12-31 CVE-2004-2470 Login vulnerability in MadBMS
Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.
network
low complexity
madbms
critical
10.0
2004-12-31 CVE-2004-2469 Reservation Modification vulnerability in PHPScheduleIt Reservation.Class.PHP
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
network
low complexity
brickhost
5.0
2004-12-31 CVE-2004-2468 Cross-Site Scripting vulnerability in Scripts for Educators Sillysearch 2.3
Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
4.3
2004-12-31 CVE-2004-2467 Denial-Of-Service vulnerability in EFS Software Easy Chat Server 1.2
chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).
network
low complexity
efs-software
5.0
2004-12-31 CVE-2004-2466 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in EFS Software Easy Chat Server 1.2/2.2
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow.
network
low complexity
efs-software CWE-119
5.0