Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-02-12 CVE-2004-2088 Unspecified vulnerability in Sophos Anti-Virus 3.4.6/3.78
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
network
low complexity
sophos
5.0
2004-02-11 CVE-2004-2083 Unspecified vulnerability in Opera Browser
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
network
high complexity
opera
2.6
2004-02-11 CVE-2003-1214 Security Bypass vulnerability in ezContents
Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.
network
low complexity
visualshapers
7.5
2004-02-10 CVE-2004-2091 Unspecified vulnerability in Microsoft Baseline Security Analyzer 1.2
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
network
low complexity
microsoft
5.0
2004-02-09 CVE-2004-2093 Denial-Of-Service vulnerability in rsync
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable.
local
low complexity
gnu
4.6
2004-02-09 CVE-2004-2080 Remote vulnerability in Red-M Red-Alert 2.7.5V3.1Build24
Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.
network
low complexity
red-m
5.0
2004-02-09 CVE-2004-2079 Remote vulnerability in Red-M Red-Alert 2.7.5V3.1Build24
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
network
low complexity
red-m
7.5
2004-02-09 CVE-2004-2078 Remote vulnerability in Red-M Red-Alert 2.7.5V3.1Build24
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.
network
low complexity
red-m
5.0
2004-02-08 CVE-2004-2087 User Authentication vulnerability in Sandsurfer 1.6.5
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
network
low complexity
sandsurfer
7.5
2004-02-08 CVE-2004-2077 Remote Denial of Service vulnerability in Nadeo Game Engine, Trackmania and Virtual Skipper
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.
network
low complexity
nadeo
5.0