Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0501 Unspecified vulnerability in Microsoft Outlook 2003
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.
network
low complexity
microsoft
5.0
2004-08-18 CVE-2004-0476 Remote 812 ADSL Router Telnet Buffer Overflow vulnerability in 3Com 3Cp4144 1.1.9.4
Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.
network
low complexity
3com
5.0
2004-08-18 CVE-2004-0412 Password Retrieval vulnerability in GNU Mailman
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.
network
low complexity
gnu
5.0
2004-08-18 CVE-2004-0375 Remote Denial Of Service vulnerability in Symantec Client Firewall Products SYMNDIS.SYS Driver
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.
network
low complexity
symantec
5.0
2004-08-18 CVE-2004-0235 Buffer Overflow/Directory Traversal vulnerability in Multiple LHA
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) ..
6.4
2004-08-18 CVE-2004-0232 Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
5.0
2004-08-18 CVE-2004-0230 TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
network
low complexity
oracle openpgp mcafee netbsd xinuos juniper
5.0
2004-08-18 CVE-2004-0229 Unspecified vulnerability in Linux kernel Framebuffer Code
The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.
local
low complexity
gentoo linux
4.6
2004-08-18 CVE-2004-0175 Path Traversal vulnerability in Openbsd Openssh
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.
network
openbsd CWE-22
4.3
2004-08-18 CVE-2003-1045 Multiple vulnerability in Bugzilla
votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.
network
low complexity
mozilla
5.0