Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-01-27 CVE-2004-0927 Multiple Security vulnerability in Apple Mac OS X
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
network
low complexity
easy-software-products apple
5.0
2005-01-27 CVE-2004-0925 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
network
low complexity
apple
5.0
2005-01-27 CVE-2004-0924 Multiple Security vulnerability in Apple Mac OS X
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
network
low complexity
easy-software-products apple
5.0
2005-01-27 CVE-2004-0922 Multiple Security vulnerability in Apple Mac OS X
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
network
low complexity
apple
5.0
2005-01-27 CVE-2004-0918 Resource Management Errors vulnerability in multiple products
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
network
low complexity
openpkg squid gentoo redhat trustix ubuntu CWE-399
5.0
2005-01-27 CVE-2004-0917 Remote Information Disclosure vulnerability in Vignette Application Portal
The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag.
network
low complexity
vignette
5.0
2005-01-27 CVE-2004-0916 Unspecified vulnerability in Cabextract Project Cabextract 0.2/0.6/1.0
Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing ..
network
low complexity
cabextract-project
5.0
2005-01-27 CVE-2004-0886 Buffer Overflow vulnerability in LibTIFF
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
5.0
2005-01-25 CVE-2005-0309 Cross-Site Scripting vulnerability in Exponent 0.95
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.
network
exponent
4.3
2005-01-25 CVE-2005-0307 Input Validation vulnerability in Mercuryboard 1.1/1.1.1
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.
network
mercuryboard
4.3