Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-03-03 CVE-2004-0132 Unspecified vulnerability in Visualshapers Ezcontents
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.
network
low complexity
visualshapers
7.5
2004-03-03 CVE-2004-0128 Remote File Include vulnerability in PhpGedView [GED_File]_conf.php
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains a malicious theme.php script.
network
low complexity
phpgedview
7.5
2004-03-03 CVE-2004-0127 Directory Traversal vulnerability in PhpGedView Editconfig_gedcom.php
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via ..
network
low complexity
phpgedview
7.5
2004-03-03 CVE-2004-0106 Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.
local
low complexity
xfree86-project openbsd
7.2
2004-03-03 CVE-2004-0105 Buffer Overflow/Format String Handling vulnerability in Metamail
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
network
low complexity
metamail-corporation sgi redhat
7.5
2004-03-03 CVE-2004-0104 Buffer Overflow/Format String Handling vulnerability in Metamail
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
network
low complexity
metamail-corporation sgi redhat
7.5
2004-03-03 CVE-2004-0082 Unspecified vulnerability in Samba 3.0.0/3.0.1
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.
network
low complexity
samba
7.5
2004-03-03 CVE-2004-0078 Remote Buffer Overflow vulnerability in Mutt Menu Drawing
Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.
network
low complexity
mutt
7.5
2004-03-03 CVE-2004-0077 Local Privilege Escalation vulnerability in Linux Kernel do_mremap Function VMA Limit
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.
local
low complexity
redhat linux netwosix trustix
7.2
2004-03-03 CVE-2004-0010 Local Privilege Escalation vulnerability in Linux Kernel NCPFS ncp_lookup()
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.
local
low complexity
linux
7.2