Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,946 CVEs tagged with CWE-201,639 Critical, 5,067 High, 5,714 Medium, 522 Low, 4 Unrated.

CVE-2005-0200

Published May 2, 2005

TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP script…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0209

Published May 2, 2005

Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0449

Published May 2, 2005

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are n…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0492

Published May 2, 2005

Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0850

Published May 2, 2005

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0904

Published May 2, 2005

Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0116

Published Jan 18, 2005

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2004-1125

Published Jan 10, 2005

Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allow…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2004-1386

Published Dec 31, 2004

TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CV…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1777

Published Dec 31, 2004

A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2533

Published Dec 31, 2004

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2592

Published Dec 31, 2004

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2596

Published Dec 31, 2004

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2649

Published Dec 31, 2004

Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the U…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2706

Published Dec 31, 2004

Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0244

Published Nov 23, 2004

Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset)…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0276

Published Nov 23, 2004

The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1617

Published Oct 18, 2004

Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML includin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1675

Published Sep 11, 2004

Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1928

Published Apr 12, 2004

The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0368

Published Feb 3, 2004

Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,851-12,875 of 12,946 CVEsPage 515 of 518