Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-09-28 CVE-2004-0699 Buffer Overflow vulnerability in Check Point VPN-1 ASN.1
Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.
network
low complexity
checkpoint
7.5
2004-09-28 CVE-2004-0691 Unspecified vulnerability in Trolltech QT
Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.
network
low complexity
trolltech
7.5
2004-09-28 CVE-2004-0689 Link Following vulnerability in multiple products
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
local
low complexity
kde debian CWE-59
7.1
2004-09-28 CVE-2004-0629 Buffer Overflow vulnerability in Adobe Acrobat/Acrobat Reader ActiveX Control URI Request Heap
Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.
network
low complexity
adobe
7.5
2004-09-28 CVE-2004-0593 Unspecified vulnerability in Sygate Technologies Enforcer and Secure Enterprise
Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.
network
low complexity
sygate-technologies
7.5
2004-09-28 CVE-2004-0573 Unspecified vulnerability in Microsoft products
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
network
low complexity
microsoft
7.5
2004-09-28 CVE-2004-0500 MSN Protocol Buffer Overflow vulnerability in Gaim
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
network
low complexity
rob-flynn gentoo mandrakesoft
7.5
2004-09-28 CVE-2004-0458 NULL Pointer Dereference vulnerability in multiple products
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
network
low complexity
nicolas-boullis debian CWE-476
7.5
2004-09-28 CVE-2004-0408 Remote Buffer Overflow vulnerability in Michael Bacarella IDent2 Daemon Child_Service
Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.
network
low complexity
michael-bacarella
7.5
2004-09-28 CVE-2003-1052 Unspecified vulnerability in IBM DB2 and DB2 Universal Database
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
local
low complexity
ibm
7.2