Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2546 Denial-Of-Service vulnerability in Samba
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
network
low complexity
samba trustix
6.4
2004-12-31 CVE-2004-2545 Denial-Of-Service vulnerability in Securecomputing Sidewinder G2 6.1.0.01
Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.
network
low complexity
securecomputing
5.0
2004-12-31 CVE-2004-2543 Denial-Of-Service vulnerability in Securecomputing Sidewinder G2 6.1.0.01
Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter.
network
low complexity
securecomputing
5.0
2004-12-31 CVE-2004-2541 Buffer Errors vulnerability in Cscope 15.5
Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.
local
cscope CWE-119
6.9
2004-12-31 CVE-2004-2540 Denial-Of-Service vulnerability in SUN JDK and JRE
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
network
low complexity
sun
5.0
2004-12-31 CVE-2004-2538 Unspecified vulnerability in Nilesh Dosooye PHPcodegenie
Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.
network
low complexity
nilesh-dosooye
6.5
2004-12-31 CVE-2004-2535 Unspecified vulnerability in Matthew Phillips Sticker 3.0.0
The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.
network
low complexity
matthew-phillips
5.0
2004-12-31 CVE-2004-2533 Improper Input Validation vulnerability in Solarwinds Serv-U File Server 4.1.0.0
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.
network
low complexity
solarwinds CWE-20
5.0
2004-12-31 CVE-2004-2529 Remote vulnerability in Gadu-Gadu
Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.
network
low complexity
gadu-gadu
5.0
2004-12-31 CVE-2004-2528 Cross-Site Scripting vulnerability in Webcam Corp Webcam Watchdog 4.0.1A
Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.
network
webcam-corp
4.3