Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2691 Denial-Of-Service vulnerability in 3Com 3C17205-Us, 3C17210-Us and Superstack 3 Switch
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface.
network
3com
7.1
2004-12-31 CVE-2004-2690 File-Upload vulnerability in newsPHP
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.
network
newsphp
8.5
2004-12-31 CVE-2004-2686 Path Traversal vulnerability in SUN Solaris and Sunos
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls.
local
low complexity
sun CWE-22
7.2
2004-12-31 CVE-2004-2685 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Youngzsoft Ccproxy
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.
network
low complexity
youngzsoft CWE-119
7.5
2004-12-31 CVE-2004-2681 Cross-Site Scripting vulnerability in MatrixSSL
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.
network
low complexity
peersec-networks
7.5
2004-12-31 CVE-2004-2679 Information Disclosure vulnerability in Checkpoint Firewall-1 4.0/4.1/R55
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
network
low complexity
checkpoint
7.8
2004-12-31 CVE-2004-2677 Remote Format String vulnerability in Qwikmail Smtp 0.3
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
network
low complexity
qwikmail
7.5
2004-12-31 CVE-2004-2676 Local Security vulnerability in Webroot Software SPY Sweeper Enterprise 1.5.1Build3698
The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges.
local
low complexity
webroot-software
7.2
2004-12-31 CVE-2004-2672 Remote Security vulnerability in Argosoft FTP Server 1.4.2
Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.
network
low complexity
argosoft
7.5
2004-12-31 CVE-2004-2669 Remote SQL Injection vulnerability in Neocrome Land Down Under 701
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php.
network
low complexity
neocrome
7.5