2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2599 | — | — | 0.4% | Dec 31, 2004 | Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den... |
| CVE-2004-2364 | — | — | 10.7% | Dec 31, 2004 | Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c... |
| CVE-2004-2363 | — | — | 1.8% | Dec 31, 2004 | Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allow... |
| CVE-2004-2362 | — | — | 1.7% | Dec 31, 2004 | PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the li... |
| CVE-2004-2372 | — | — | 0.7% | Dec 31, 2004 | Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME... |
| CVE-2004-2360 | — | — | 3.4% | Dec 31, 2004 | Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incom... |
| CVE-2004-2359 | — | — | 5.7% | Dec 31, 2004 | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started ... |
| CVE-2004-2358 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in admin_words.php for phpBB 2.0.6c allows remote attackers to inject arbitrary... |
| CVE-2004-2357 | — | — | 1.4% | Dec 31, 2004 | The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, w... |
| CVE-2004-2356 | — | — | 2.6% | Dec 31, 2004 | Early termination vulnerability in Fizmez Web Server 1.0 allows remote attackers to cause a denial of service (crash) by... |
| CVE-2004-2355 | — | — | 2.0% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to injec... |
| CVE-2004-2354 | — | — | 1.5% | Dec 31, 2004 | SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL state... |
| CVE-2004-2373 | — | — | 2.7% | Dec 31, 2004 | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allo... |
| CVE-2004-2352 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2004-2351 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2004-2350 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a... |
| CVE-2004-2600 | — | — | 2.6% | Dec 31, 2004 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped... |
| CVE-2004-2348 | — | — | 1.6% | Dec 31, 2004 | Sybari AntiGen for Domino 7.0 Build 722 SR2 allows remote attackers to cause a denial of service (hang) via an encrypted... |
| CVE-2004-2347 | — | — | 9.9% | Dec 31, 2004 | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metach... |
| CVE-2004-2346 | — | — | 0.9% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject... |
| CVE-2004-2713 | — | — | 0.3% | Dec 31, 2004 | Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local u... |
| CVE-2004-2344 | — | — | 3.0% | Dec 31, 2004 | Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a de... |
| CVE-2004-2343 | — | — | 0.6% | Dec 31, 2004 | Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.co... |
| CVE-2004-2342 | — | — | 1.9% | Dec 31, 2004 | ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server... |
| CVE-2004-2374 | — | — | 2.8% | Dec 31, 2004 | BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now