Skip to main content

Severity archive

Critical severity CVEs

Critical

43,370 critical severity CVEs — 43,370 Critical, 124,776 High, 163,222 Medium, 17,939 Low, 2,047 Unrated across the current result set.

CVE-2004-2644

Published Dec 31, 2004

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2645

Published Dec 31, 2004

Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2673

Published Dec 31, 2004

Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZI…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2687

Published Dec 31, 2004

distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2689

Published Dec 31, 2004

NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2692

Published Dec 31, 2004

The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick oper…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2700

Published Dec 31, 2004

Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2734

Published Dec 31, 2004

webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0646

Published Dec 23, 2004

Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0441

Published Dec 22, 2004

Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) at…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1351

Published Dec 7, 2004

Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1582

Published Dec 6, 2004

compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0393

Published Dec 6, 2004

Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can n…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0448

Published Dec 6, 2004

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0451

Published Dec 6, 2004

Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0477

Published Dec 6, 2004

Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0480

Published Dec 6, 2004

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to prov…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0603

Published Dec 6, 2004

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0621

Published Dec 6, 2004

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lis…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0623

Published Dec 6, 2004

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0627

Published Dec 6, 2004

The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0628

Published Dec 6, 2004

Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scram…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 42,426-42,450 of 43,370 CVEsPage 1698 of 1735