NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70795 | CVE-2004-0344 | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2016-10-17 | View | |
70794 | CVE-2004-0343 | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
70793 | CVE-2004-0342 | WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
70792 | CVE-2004-0341 | WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
70791 | CVE-2004-0340 | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View |
Page 15962 of 17672, showing 5 records out of 88360 total, starting on record 79806, ending on 79810