2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0189——The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a U...
CVE-2004-0190——Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may b...
CVE-2004-1815——Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as...
CVE-2004-1816——Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an...
CVE-2004-1817——Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary we...
CVE-2004-1818——Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attac...
CVE-2004-1819——4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request t...
CVE-2004-1820——PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remot...
CVE-2004-1821——SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or p...
CVE-2004-1822——Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar...
CVE-2004-1827——Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject...
CVE-2004-0191——Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to in...
CVE-2004-0168——Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."
CVE-2004-0169——QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via...
CVE-2004-0193——Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network ...
CVE-2004-0094——Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbi...
CVE-2004-0093——XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bou...
CVE-2004-0171——FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exha...
CVE-2004-0172——Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow l...
CVE-2004-1358——The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security M...
CVE-2004-1770——The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shel...
CVE-2004-1769——The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, ...
CVE-2004-1359——Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uu...
CVE-2004-0008——Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of s...
CVE-2004-0096——Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certa...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now