- EPSS 2.27%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
CVE-2004-0079
- EPSS 2.06%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
- EPSS 1.36%
- Published 18.10.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing...
CVE-2004-0519
- EPSS 0.12%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in ...
- EPSS 13.6%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
- EPSS 4.65%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
CVE-2004-0520
- EPSS 14.93%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.
- EPSS 3.02%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
- EPSS 3.71%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.
- EPSS 3.07%
- Published 18.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.