Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2391 Remote Denial Of Service vulnerability in Jabber Software Jabber Gadu-Gadu Transport
Jabber Gadu-Gadu Transport (a.k.a.
network
low complexity
jabberstudio
5.0
2004-12-31 CVE-2004-2390 Remote Denial Of Service vulnerability in Jabber Software Jabber Gadu-Gadu Transport
The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a.
network
low complexity
jabberstudio
5.0
2004-12-31 CVE-2004-2389 Remote Denial Of Service vulnerability in Jabber Software Jabber Gadu-Gadu Transport
Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a.
network
low complexity
jabberstudio
5.0
2004-12-31 CVE-2004-2388 Privilege Escalation vulnerability in IBM AIX 4.3.3
rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the structure to be overwritten by the authenticate function and assign privileges to the wrong user.
network
low complexity
ibm
critical
10.0
2004-12-31 CVE-2004-2387 Remote vulnerability in Sredird
Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.
network
low complexity
denis-sbragion peter-astrand
7.5
2004-12-31 CVE-2004-2386 USE of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.
network
low complexity
denis-sbragion peter-astrand CWE-134
7.5
2004-12-31 CVE-2004-2385 Multiple vulnerability in Emumail EMU Webmail 5.2.7
EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.
network
low complexity
emumail
5.0
2004-12-31 CVE-2004-2384 Denial of Service vulnerability in Nullsoft Winamp 5.02
NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.
network
low complexity
nullsoft
5.0
2004-12-31 CVE-2004-2383 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus.
network
high complexity
microsoft
5.1
2004-12-31 CVE-2004-2382 Denial Of Service vulnerability in PerfectNav Malformed URI
The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".
network
low complexity
perfectnav
5.0