Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2004-11-03 CVE-2004-0828 Local File Corruption vulnerability in IBM CTSTRTCASD Utility
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.
local
low complexity
ibm
2.1
2004-11-03 CVE-2004-0211 Unspecified vulnerability in Microsoft Windows 2003 Server R2
The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
local
low complexity
microsoft
2.1
2004-11-03 CVE-2004-0207 Unspecified vulnerability in Microsoft products
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
local
low complexity
microsoft
2.1
2004-10-20 CVE-2004-0797 Unspecified vulnerability in Zlib 1.2.1
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).
local
low complexity
zlib
2.1
2004-10-20 CVE-2004-0755 Unspecified vulnerability in Yukihiro Matsumoto Ruby 1.6/1.8
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.
local
low complexity
yukihiro-matsumoto
2.1
2004-10-20 CVE-2004-0752 Local File Disclosure vulnerability in Openoffice 1.1.2
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.
local
low complexity
openoffice
2.1
2004-10-20 CVE-2004-0559 The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
local
low complexity
usermin webmin mandrakesoft
2.1
2004-10-18 CVE-2004-1615 Unspecified vulnerability in Opera Browser
Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.
network
high complexity
opera
2.6
2004-10-06 CVE-2005-0192 Directory Traversal vulnerability in RealPlayer
Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a ..
network
high complexity
realnetworks
2.6
2004-09-29 CVE-2005-0190 Remote Arbitrary File Deletion vulnerability in RealNetworks RealOne Player And RealPlayer
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing ..
network
high complexity
realnetworks
2.6