Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2443 Input Validation vulnerability in Jaws 0.2/0.3
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
network
low complexity
jaws
7.5
2004-12-31 CVE-2004-2442 Unspecified vulnerability in F-Secure products
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.
network
low complexity
f-secure
5.0
2004-12-31 CVE-2004-2441 Unspecified vulnerability in Kerio Mailserver 6.0/6.0.1/6.0.2
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."
network
low complexity
kerio
critical
10.0
2004-12-31 CVE-2004-2440 Local Proxy Credential Disclosure vulnerability in Proxytunnel 1.0.6/1.1.3
Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users.
local
low complexity
proxytunnel
2.1
2004-12-31 CVE-2004-2439 Unspecified vulnerability in HP products
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
network
low complexity
hp
5.0
2004-12-31 CVE-2004-2438 SQL and HTML Injection vulnerability in PHP Fusion PHP Fusion 4.01
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.
network
php-fusion
4.3
2004-12-31 CVE-2004-2437 SQL and HTML Injection vulnerability in PHP Fusion PHP Fusion 4.01
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.
network
low complexity
php-fusion
7.5
2004-12-31 CVE-2004-2436 Unspecified vulnerability in Broadcom products
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.
local
low complexity
broadcom
2.1
2004-12-31 CVE-2004-2435 Cross-Site Scripting vulnerability in Peoplesoft Hrms 7.0
Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.
network
peoplesoft
4.3
2004-12-31 CVE-2004-2434 Denial-Of-Service vulnerability in Microsoft IE 6.0
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.
network
low complexity
microsoft
5.0