2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2340** UNVERIFIABLE ** SQL injection vulnerability in PunkBuster Screenshot Database (PB-DB) Alpha 6 allows remote attacker...
CVE-2004-2338OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such a...
CVE-2004-2337The /.inlook/.crypt file for inlook 0.7.3 and earlier is installed with world readable permissions, which allows local u...
CVE-2004-2599Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den...
CVE-2004-2335The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver...
CVE-2004-2334Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web ...
CVE-2004-2333Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded fil...
CVE-2004-2372Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME...
CVE-2004-2330ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a lar...
CVE-2004-2329Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load but...
CVE-2004-2328Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via a...
CVE-2004-2373The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allo...
CVE-2004-2326SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to byp...
CVE-2004-2325Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0...
CVE-2004-2324SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to m...
CVE-2004-2323DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, in...
CVE-2004-2322SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attacke...
CVE-2004-2321BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator pass...
CVE-2004-2319IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log f...
CVE-2004-2600The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped...
CVE-2004-2317Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive informatio...
CVE-2004-2316Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request ...
CVE-2004-2315Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIO...
CVE-2004-2713Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local u...
CVE-2004-2374BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now