NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71446  CVE-2004-1054  Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.    7.2  High  2017-07-18  2017-07-10  View
71702  CVE-2004-1322  Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.    7.5  High  2017-07-18  2017-07-10  View
71958  CVE-2004-1579  index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.    Medium  2017-07-18  2017-07-10  View
72214  CVE-2004-1836  SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.    7.5  High  2017-07-18  2017-07-10  View
72470  CVE-2004-2093  Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.    4.6  Medium  2017-07-18  2017-07-10  View

Page 15660 of 17672, showing 5 records out of 88360 total, starting on record 78296, ending on 78300

Actions