|
289571
|
- |
|
sun
|
solaris
|
The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide …
|
NVD-CWE-Other
|
CVE-2004-1357
|
2017-10-11 10:29 |
2004-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289572
|
- |
|
sun
|
solaris
|
The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.
|
NVD-CWE-Other
|
CVE-2004-1358
|
2017-10-11 10:29 |
2004-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289573
|
- |
|
hp
|
hp-ux
|
Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-1375
|
2017-10-11 10:29 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289574
|
- |
|
mozilla
|
firefox mozilla
|
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and fa…
|
NVD-CWE-Other
|
CVE-2004-1380
|
2017-10-11 10:29 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289575
|
- |
|
mozilla
|
firefox mozilla
|
Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers…
|
NVD-CWE-Other
|
CVE-2004-1381
|
2017-10-11 10:29 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289576
|
- |
|
php
|
php
|
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
|
NVD-CWE-Other
|
CVE-2004-1392
|
2017-10-11 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289577
|
- |
|
gnu
|
glibc
|
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive i…
|
NVD-CWE-Other
|
CVE-2004-1453
|
2017-10-11 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289578
|
- |
|
full_revolution
|
aspwebcalendar
|
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.
|
NVD-CWE-Other
|
CVE-2004-1552
|
2017-10-11 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289579
|
- |
|
fullrevolution
|
aspwebalbum
|
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it wa…
|
CWE-89
SQL Injection
|
CVE-2004-1553
|
2017-10-11 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289580
|
- |
|
mozilla sgi redhat
|
mozilla propack enterprise_linux enterprise_linux_desktop fedora_core linux linux_advanced_workstation
|
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG…
|
NVD-CWE-Other
|
CVE-2004-1613
|
2017-10-11 10:29 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|