Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-12-06 CVE-2004-0496 Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
local
low complexity
mandrakesoft suse gentoo linux sun
7.2
2004-12-06 CVE-2004-0456 Remote Stack-Based Buffer Overrun vulnerability in Pavuk
Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.
network
high complexity
pavuk debian gentoo
7.6
2004-12-06 CVE-2004-0455 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
local
low complexity
www-sql-project debian CWE-120
7.2
2004-12-06 CVE-2004-0454 Multiple vulnerability in Rlpr msg() Function
Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.
local
low complexity
rlpr
7.2
2004-12-06 CVE-2004-0395 Privilege Escalation vulnerability in Gatos .5
The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.
local
low complexity
gatos
7.2
2004-12-03 CVE-2004-1083 Improper Handling of Case Sensitivity vulnerability in Apple products
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
network
low complexity
apple CWE-178
7.5
2004-12-02 CVE-2004-1088 Remote And Local vulnerability in Apple Mac OS X
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
network
low complexity
apple
7.5
2004-12-02 CVE-2004-1086 Remote And Local vulnerability in Apple Mac OS X
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
network
low complexity
apple
7.5
2004-11-23 CVE-2004-0494 Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.
network
low complexity
avaya redhat
7.5
2004-11-23 CVE-2004-0360 Passwd Local Root Compromise vulnerability in Sun Solaris
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.
local
low complexity
sun
7.2