2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2599 | — | — | 0.4% | Dec 31, 2004 | Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den... |
| CVE-2004-2363 | — | — | 1.8% | Dec 31, 2004 | Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allow... |
| CVE-2004-2362 | — | — | 1.7% | Dec 31, 2004 | PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the li... |
| CVE-2004-2361 | — | — | 2.2% | Dec 31, 2004 | Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote... |
| CVE-2004-2712 | — | — | 1.2% | Dec 31, 2004 | Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of servic... |
| CVE-2004-2359 | — | — | 5.7% | Dec 31, 2004 | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started ... |
| CVE-2004-2358 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in admin_words.php for phpBB 2.0.6c allows remote attackers to inject arbitrary... |
| CVE-2004-2357 | — | — | 1.4% | Dec 31, 2004 | The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, w... |
| CVE-2004-2356 | — | — | 2.6% | Dec 31, 2004 | Early termination vulnerability in Fizmez Web Server 1.0 allows remote attackers to cause a denial of service (crash) by... |
| CVE-2004-2355 | — | — | 2.0% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to injec... |
| CVE-2004-2354 | — | — | 1.5% | Dec 31, 2004 | SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL state... |
| CVE-2004-2353 | — | — | 1.4% | Dec 31, 2004 | BugPort before 1.099 stores its configuration file (conf/config.conf) under the web document root with a file extension ... |
| CVE-2004-2373 | — | — | 2.7% | Dec 31, 2004 | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allo... |
| CVE-2004-2351 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2004-2350 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a... |
| CVE-2004-2349 | — | — | 1.2% | Dec 31, 2004 | Multiple SQL injection vulnerabilities in Tunez before 1.20-pre2 allow remote attackers to execute arbitrary SQL queries... |
| CVE-2004-2374 | — | — | 2.8% | Dec 31, 2004 | BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php... |
| CVE-2004-2347 | — | — | 9.9% | Dec 31, 2004 | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metach... |
| CVE-2004-2346 | — | — | 0.9% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject... |
| CVE-2004-2345 | — | — | 1.4% | Dec 31, 2004 | Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users wi... |
| CVE-2004-2600 | — | — | 2.6% | Dec 31, 2004 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped... |
| CVE-2004-2343 | — | — | 0.6% | Dec 31, 2004 | Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.co... |
| CVE-2004-2342 | — | — | 1.9% | Dec 31, 2004 | ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server... |
| CVE-2004-2341 | — | — | 2.8% | Dec 31, 2004 | PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary cod... |
| CVE-2004-2375 | — | — | 5.9% | Dec 31, 2004 | Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (cr... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now