Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2004-07-27 CVE-2004-0698 Local Security vulnerability in WebSTAR
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.
local
low complexity
4d
3.6
2004-07-07 CVE-2004-0484 Unspecified vulnerability in Microsoft Internet Explorer 6.0.2900
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
network
high complexity
microsoft
2.6
2004-07-07 CVE-2004-0478 Resource Management Errors vulnerability in Mozilla
Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.
network
high complexity
mozilla CWE-399
2.6
2004-07-07 CVE-2004-0473 Argument Injection or Modification vulnerability in Opera Browser
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-f" option on Windows XP or (2) the "-n" option on Linux.
network
high complexity
opera CWE-88
2.6
2004-07-07 CVE-2004-0471 Denial of Service vulnerability in BEA Weblogic Server 7.0/8.1
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).
local
low complexity
bea
2.1
2004-07-07 CVE-2004-0445 Remote DNS Response Denial Of Service vulnerability in Symantec Client Firewall
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.
network
high complexity
symantec
2.6
2004-07-07 CVE-2004-0423 Local Security vulnerability in ssmtp
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.
local
low complexity
ssmtp
2.1
2004-07-07 CVE-2004-0422 Unspecified vulnerability in GNU Flim 1.14.2
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.
local
low complexity
gnu
2.1
2004-07-07 CVE-2004-0404 Unspecified vulnerability in Psionic Logcheck
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.
local
high complexity
psionic
1.2
2004-06-19 CVE-2004-1346 Denial Of Service vulnerability in SUN Solaris 9.0
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.
local
low complexity
sun
2.1