Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-11-23 CVE-2004-0278 Denial of Service vulnerability in Ratbag Game Engine
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.
network
low complexity
ratbag
5.0
2004-11-23 CVE-2004-0276 Improper Input Validation vulnerability in Monkey-Project Monkey
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.
network
low complexity
monkey-project CWE-20
5.0
2004-11-23 CVE-2004-0275 SQL Injection vulnerability in Bosdev Bosdates 3.0/3.1/3.2
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.
network
low complexity
bosdev
5.0
2004-11-23 CVE-2004-0271 Input Validation vulnerability in Maxwebportal 1.30/1.31
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.
network
maxwebportal
6.8
2004-11-23 CVE-2004-0270 Denial Of Service vulnerability in Clam Anti-Virus Clamav 0.65
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.
network
low complexity
clam-anti-virus
5.0
2004-11-23 CVE-2004-0269 SQL Injection vulnerability in PHPNuke Category Parameter
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
network
low complexity
francisco-burzi
6.4
2004-11-23 CVE-2004-0268 Remote Buffer Overflow vulnerability in EvolutionX
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.
network
low complexity
evolutionx
5.0
2004-11-23 CVE-2004-0266 SQL Injection vulnerability in PHP-Nuke Public Message
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.
network
low complexity
francisco-burzi
5.0
2004-11-23 CVE-2004-0265 Cross-Site Scripting vulnerability in PHP-Nuke 'News' Module
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.
network
francisco-burzi
6.8
2004-11-23 CVE-2004-0264 Remote Denial of Service vulnerability in Shaun2k2 Palmhttpd Server
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.
network
low complexity
jim-rees shaun2k2
5.0