2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-2599Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den...
CVE-2004-2363Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allow...
CVE-2004-2362PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the li...
CVE-2004-2361Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote...
CVE-2004-2712Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of servic...
CVE-2004-2359Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started ...
CVE-2004-2358Cross-site scripting (XSS) vulnerability in admin_words.php for phpBB 2.0.6c allows remote attackers to inject arbitrary...
CVE-2004-2357The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, w...
CVE-2004-2356Early termination vulnerability in Fizmez Web Server 1.0 allows remote attackers to cause a denial of service (crash) by...
CVE-2004-2355Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to injec...
CVE-2004-2354SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL state...
CVE-2004-2353BugPort before 1.099 stores its configuration file (conf/config.conf) under the web document root with a file extension ...
CVE-2004-2373The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allo...
CVE-2004-2351Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web scrip...
CVE-2004-2350SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a...
CVE-2004-2349Multiple SQL injection vulnerabilities in Tunez before 1.20-pre2 allow remote attackers to execute arbitrary SQL queries...
CVE-2004-2374BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php...
CVE-2004-2347blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metach...
CVE-2004-2346Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject...
CVE-2004-2345Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users wi...
CVE-2004-2600The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped...
CVE-2004-2343Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.co...
CVE-2004-2342ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server...
CVE-2004-2341PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary cod...
CVE-2004-2375Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (cr...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now