2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1302The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file ...
CVE-2004-1298Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a cr...
CVE-2004-1313The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before inv...
CVE-2004-1311Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to...
CVE-2004-1310Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to exe...
CVE-2004-1297Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbi...
CVE-2004-1281The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) ...
CVE-2004-1231Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequence...
CVE-2004-1154Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to ca...
CVE-2004-1183Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of serv...
CVE-2004-1318Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject a...
CVE-2004-1061Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attacke...
CVE-2004-1312A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote ...
CVE-2004-2567Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via t...
CVE-2004-2568Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web sc...
CVE-2004-2697The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via...
CVE-2004-2569ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack...
CVE-2004-2570Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript...
CVE-2004-2698Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial ...
CVE-2004-2571Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQ...
CVE-2004-2572AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters...
CVE-2004-2573PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote at...
CVE-2004-2574Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to ...
CVE-2004-2699deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified Pro...
CVE-2004-2700Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload a...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now