CVE-2004-1029
- EPSS 42.56%
- Published 01.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load un...
- EPSS 33.01%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
CVE-2004-0884
- EPSS 0.06%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malici...
- EPSS 18.83%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send p...
- EPSS 6.06%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
- EPSS 18.83%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachment...
- EPSS 10.25%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment ...
- EPSS 10.25%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index in...
- EPSS 16.62%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.
- EPSS 31.75%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overfl...