Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1022 Unspecified vulnerability in Kerio Mailserver, Serverfirewall and Winroute Firewall
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
local
low complexity
kerio
2.1
2005-01-10 CVE-2004-1016 Local Denial of Service vulnerability in Linux Kernel SCM_SEND
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.
local
low complexity
linux ubuntu
2.1
2005-01-10 CVE-2004-0996 main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
local
low complexity
cscope debian gentoo sco
2.1
2005-01-10 CVE-2004-0770 Symbolic Link vulnerability in DGen Emulator
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
local
low complexity
dgen debian
2.1
2004-12-31 CVE-2004-2759 Information Disclosure vulnerability in Sun StorEdge Sparse File
Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.
local
low complexity
sun
2.1
2004-12-31 CVE-2004-2728 Buffer Errors vulnerability in Hummingbird Connectivity 7.1/9.0
Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.
3.5
2004-12-31 CVE-2004-2723 Credentials Management vulnerability in Nessus Nessuswx 1.4.4
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
local
low complexity
nessus CWE-255
2.1
2004-12-31 CVE-2004-2717 Path Traversal vulnerability in PHP Heaven PHPmychat 0.14.5
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a ..
network
high complexity
php-heaven CWE-22
2.6
2004-12-31 CVE-2004-2684 Local Security vulnerability in Intersystems Cache Database 5
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files under (a) Dev\studio\templates and (b) Devuser\studio\templates.
local
low complexity
intersystems
2.1
2004-12-31 CVE-2004-2683 Local Security vulnerability in Intersystems Cache 5
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.
local
low complexity
intersystems
2.1