Skip to main content

Severity archive

Low severity CVEs

Low

17,960 low severity CVEs — 43,418 Critical, 124,914 High, 163,414 Medium, 17,960 Low, 2,008 Unrated across the current result set.

CVE-2004-1296

Published Dec 31, 2004

The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1382

Published Dec 31, 2004

The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-096…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1387

Published Dec 31, 2004

The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1396

Published Dec 31, 2004

Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that conta…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1411

Published Dec 31, 2004

Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restri…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1438

Published Dec 31, 2004

The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repos…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1445

Published Dec 31, 2004

A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1451

Published Dec 31, 2004

Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrus…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1453

Published Dec 31, 2004

GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1465

Published Dec 31, 2004

Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1489

Published Dec 31, 2004

Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user nam…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1490

Published Dec 31, 2004

Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Dispositio…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1495

Published Dec 31, 2004

The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1586

Published Dec 31, 2004

Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connect…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1748

Published Dec 31, 2004

NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1795

Published Dec 31, 2004

Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1808

Published Dec 31, 2004

Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1894

Published Dec 31, 2004

TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1895

Published Dec 31, 2004

YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1902

Published Dec 31, 2004

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1907

Published Dec 31, 2004

The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1909

Published Dec 31, 2004

Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 17,151-17,175 of 17,960 CVEsPage 687 of 719