Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-01-11 CVE-2004-1039 Denial of Service vulnerability in SCO UnixWare NFS Mountd
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.
network
low complexity
sco
5.0
2005-01-10 CVE-2005-0287 Remote Security vulnerability in Bottomline Webseries Payment Application 4.0
Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.
network
low complexity
bottomline
5.0
2005-01-10 CVE-2004-1294 Unspecified vulnerability in Luke Mewburn Tnftp 20030825
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
network
low complexity
luke-mewburn
5.0
2005-01-10 CVE-2004-1281 Remote Security vulnerability in Junkie FTP Client 0.3.1
The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via ..
network
low complexity
junkie
5.0
2005-01-10 CVE-2004-1277 Remote Security vulnerability in Iglooftp 0.6.1
The download_selection_recursive() function in ftplist.c for IglooFTP 0.6.1 allows remote malicious FTP servers to overwrite arbitrary files via filenames that contain / (slash) characters.
network
low complexity
iglooftp
5.0
2005-01-10 CVE-2004-1269 lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
network
low complexity
easy-software-products redhat
5.0
2005-01-10 CVE-2004-1267 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
network
low complexity
easy-software-products redhat CWE-119
6.5
2005-01-10 CVE-2004-1233 Denial-Of-Service vulnerability in Gadu-Gadu Instant Messenger
Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.
network
low complexity
gadu-gadu
5.0
2005-01-10 CVE-2004-1231 Directory Traversal vulnerability in Gadu-Gadu Instant Messenger
Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via ..
network
low complexity
gadu-gadu
5.0
2005-01-10 CVE-2004-1230 Information Disclosure vulnerability in Gadu-Gadu Instant Messenger
Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.
network
low complexity
gadu-gadu
5.0