Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2394 Unspecified vulnerability in Mandrakesoft products
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
local
low complexity
mandrakesoft
2.1
2004-12-31 CVE-2004-2365 Denial-Of-Service vulnerability in Microsoft Windows 2003 Server and Windows XP
Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
local
low complexity
microsoft
2.1
2004-12-31 CVE-2004-2337 Unspecified vulnerability in Inlook
The /.inlook/.crypt file for inlook 0.7.3 and earlier is installed with world readable permissions, which allows local users to obtain user POP3 credentials.
local
low complexity
inlook
2.1
2004-12-31 CVE-2004-2321 Unspecified vulnerability in BEA Weblogic Server 8.1
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
local
low complexity
bea
2.1
2004-12-31 CVE-2004-2319 Local Privilege Escalation vulnerability in IBM products
IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.
local
low complexity
ibm
3.6
2004-12-31 CVE-2004-2311 Directory Traversal vulnerability in IBM Lotus Domino 6.5.1
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a ..
local
low complexity
ibm
3.6
2004-12-31 CVE-2004-2309 Remote Information Disclosure vulnerability in Crob FTP Server 3.5.1
Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command.
local
low complexity
crob
2.1
2004-12-31 CVE-2004-2303 Privilege Escalation vulnerability in MTools MFormat
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.
local
low complexity
mtools
3.6
2004-12-31 CVE-2004-2302 Local Integer Overflow vulnerability in Linux Kernel 2.6.10
Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to read kernel memory and cause a denial of service (crash) via large offsets in sysfs files.
local
high complexity
linux
2.6
2004-12-31 CVE-2004-2276 F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection.
local
low complexity
f-secure
2.1