Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-02-17 CVE-2004-0063 Unspecified vulnerability in Ncipher Payshield SPP Library 1.3.12/1.5.18/1.6.18
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g.
network
low complexity
ncipher
7.5
2004-02-17 CVE-2004-0062 Remote Security vulnerability in FishCart
Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.
network
low complexity
fishnet
7.5
2004-02-17 CVE-2004-0061 Security Bypass vulnerability in WWW File Share Pro
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing .
network
low complexity
lionmax-software
7.5
2004-02-17 CVE-2004-0056 Unspecified vulnerability in Nortel products
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
network
low complexity
nortel
7.5
2004-02-17 CVE-2004-0054 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
network
low complexity
cisco
7.5
2004-02-17 CVE-2004-0004 Unspecified vulnerability in Openca
The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.
network
low complexity
openca
7.5
2004-02-17 CVE-2004-0001 Unspecified vulnerability in Linux Kernel 2.6.20.1
Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.
local
low complexity
linux
7.2
2004-02-17 CVE-2003-1030 Buffer Overflow vulnerability in Dameware Development Mini Remote Control Server 3.70.0.0/3.71.0.0/3.72.0.0
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.
network
low complexity
dameware-development
7.5
2004-02-17 CVE-2003-0989 Denial Of Service vulnerability in Redhat Linux and Tcpdump
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
network
low complexity
redhat
7.5
2004-02-17 CVE-2003-0988 Remote Buffer Overflow vulnerability in KDE Personal Information Management Suite VCF File
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
network
low complexity
kde
7.5