Skip to main content

Severity archive

Critical severity CVEs

Critical

44,636 critical severity CVEs — 44,636 Critical, 129,526 High, 164,397 Medium, 18,308 Low, 1,823 Unrated across the current result set.

CVE-2005-0441

Published Dec 22, 2004

Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) at…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1351

Published Dec 7, 2004

Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1582

Published Dec 6, 2004

compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0393

Published Dec 6, 2004

Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can n…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0448

Published Dec 6, 2004

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0451

Published Dec 6, 2004

Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0477

Published Dec 6, 2004

Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0480

Published Dec 6, 2004

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to prov…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0603

Published Dec 6, 2004

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0621

Published Dec 6, 2004

admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lis…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0623

Published Dec 6, 2004

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0627

Published Dec 6, 2004

The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0628

Published Dec 6, 2004

Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scram…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1208

Published Dec 3, 2004

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing lo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0308

Published Nov 24, 2004

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is l…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0236

Published Nov 23, 2004

SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0239

Published Nov 23, 2004

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0241

Published Nov 23, 2004

X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0246

Published Nov 23, 2004

Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to exe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0249

Published Nov 23, 2004

PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0250

Published Nov 23, 2004

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat paramet…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0253

Published Nov 23, 2004

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 43,701-43,725 of 44,636 CVEsPage 1749 of 1786