2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1852——DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, whic...
CVE-2004-1838——Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in ...
CVE-2004-1839——MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) ...
CVE-2004-1840——Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to in...
CVE-2004-1847——News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ...
CVE-2004-1833——The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to...
CVE-2004-1834——mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard dis...
CVE-2004-1843——SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID ...
CVE-2004-1846——Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via...
CVE-2004-1853——Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long...
CVE-2004-1829——Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow r...
CVE-2004-1830——error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (...
CVE-2004-1826——SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to ex...
CVE-2004-1825——Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote at...
CVE-2004-0159——Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly ex...
CVE-2004-0192——Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attac...
CVE-2004-0075——The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to...
CVE-2004-0167——DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.
CVE-2004-0166——Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."
CVE-2004-0165——Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows ...
CVE-2004-0185——Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to ca...
CVE-2004-0186——smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting ...
CVE-2004-0187——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0185. Reason: This candidate is a reservation ...
CVE-2004-0110——Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remot...
CVE-2004-0188——Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long passwo...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now