Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-2157 | Input Validation vulnerability in S9Y Serendipity 0.7Beta1 Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field. network s9y | 4.3 |
2004-12-31 | CVE-2004-2152 | Cross-Site Scripting vulnerability in MediaWiki Raw Page Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML. network mediawiki | 4.3 |
2004-12-31 | CVE-2004-2151 | Denial Of Service vulnerability in Virtual Projects Chatma Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size. | 5.0 |
2004-12-31 | CVE-2004-2149 | Remote Buffer Overflow vulnerability in MySQL Bounded Parameter Statement Execution Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders. | 5.0 |
2004-12-31 | CVE-2004-2147 | Denial Of Service vulnerability in Symantec Norton AntiVirus Malformed EMail Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body. | 5.0 |
2004-12-31 | CVE-2004-2146 | Remote Security vulnerability in Megabbs 2/2.1 CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp. | 5.0 |
2004-12-31 | CVE-2004-2137 | Information Disclosure vulnerability in Microsoft Outlook Express 6.0 Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information. | 5.0 |
2004-12-31 | CVE-2004-2129 | Remote HTTP GET Request Denial Of Service vulnerability in Loom Software SurfNow SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. | 5.0 |
2004-12-31 | CVE-2004-2128 | Cross-Site Scripting vulnerability in BRS WebWeaver Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll. network brs | 6.8 |
2004-12-31 | CVE-2004-2126 | Unspecified vulnerability in ISS Blackice PC Protection The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers. | 4.6 |