2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0046——Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script o...
CVE-2004-0044——Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is...
CVE-2004-2133——Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of cer...
CVE-2004-2132——Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary fil...
CVE-2004-2034——Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to e...
CVE-2004-2134——Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the...
CVE-2004-2131——Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit...
CVE-2004-2117——Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a G...
CVE-2004-2122——Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary...
CVE-2004-2120——Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET re...
CVE-2004-1760——The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6,...
CVE-2004-1759——Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to ...
CVE-2004-1766——The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communicatio...
CVE-2004-0033——admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpi...
CVE-2004-0032——Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HT...
CVE-2004-2127——Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in ...
CVE-2004-0031——PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTT...
CVE-2004-0030CRITICAL9.8PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php fo...
CVE-2004-0029——Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allow...
CVE-2004-0014——Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary co...
CVE-2004-0037——FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF mes...
CVE-2004-0036——SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sens...
CVE-2004-0035——SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQ...
CVE-2004-0034——Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitra...
CVE-2004-0011——Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now