Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2157 Input Validation vulnerability in S9Y Serendipity 0.7Beta1
Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.
network
s9y
4.3
2004-12-31 CVE-2004-2152 Cross-Site Scripting vulnerability in MediaWiki Raw Page
Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.
network
mediawiki
4.3
2004-12-31 CVE-2004-2151 Denial Of Service vulnerability in Virtual Projects Chatma
Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.
network
low complexity
virtual-projects
5.0
2004-12-31 CVE-2004-2149 Remote Buffer Overflow vulnerability in MySQL Bounded Parameter Statement Execution
Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.
network
low complexity
oracle
5.0
2004-12-31 CVE-2004-2147 Denial Of Service vulnerability in Symantec Norton AntiVirus Malformed EMail
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
network
low complexity
symantec
5.0
2004-12-31 CVE-2004-2146 Remote Security vulnerability in Megabbs 2/2.1
CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.
network
low complexity
pd9-software
5.0
2004-12-31 CVE-2004-2137 Information Disclosure vulnerability in Microsoft Outlook Express 6.0
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
network
low complexity
microsoft
5.0
2004-12-31 CVE-2004-2129 Remote HTTP GET Request Denial Of Service vulnerability in Loom Software SurfNow
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
network
low complexity
loom-software
5.0
2004-12-31 CVE-2004-2128 Cross-Site Scripting vulnerability in BRS WebWeaver
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.
network
brs
6.8
2004-12-31 CVE-2004-2126 Unspecified vulnerability in ISS Blackice PC Protection
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.
local
low complexity
iss
4.6