2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2338 | — | — | 1.5% | Dec 31, 2004 | OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such a... |
| CVE-2004-2337 | — | — | 0.3% | Dec 31, 2004 | The /.inlook/.crypt file for inlook 0.7.3 and earlier is installed with world readable permissions, which allows local u... |
| CVE-2004-2336 | — | — | 2.2% | Dec 31, 2004 | Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1... |
| CVE-2004-2712 | — | — | 1.2% | Dec 31, 2004 | Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of servic... |
| CVE-2004-2334 | — | — | 4.8% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web ... |
| CVE-2004-2333 | — | — | 1.4% | Dec 31, 2004 | Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded fil... |
| CVE-2004-2332 | — | — | 1.2% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in CPAN WWW::Form before 1.13 allow remote attackers to inject arbit... |
| CVE-2004-2373 | — | — | 2.7% | Dec 31, 2004 | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allo... |
| CVE-2004-2329 | — | — | 0.6% | Dec 31, 2004 | Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load but... |
| CVE-2004-2328 | — | — | 1.6% | Dec 31, 2004 | Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via a... |
| CVE-2004-2327 | — | — | 1.7% | Dec 31, 2004 | Vizer Web Server 1.9.1 allows remote attackers to cause a denial of service (crash) via multiple malformed requests incl... |
| CVE-2004-2374 | — | — | 2.8% | Dec 31, 2004 | BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php... |
| CVE-2004-2325 | — | — | 1.2% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0... |
| CVE-2004-2324 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to m... |
| CVE-2004-2323 | — | — | 1.4% | Dec 31, 2004 | DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, in... |
| CVE-2004-2322 | — | — | 1.5% | Dec 31, 2004 | SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attacke... |
| CVE-2004-2321 | — | — | 0.2% | Dec 31, 2004 | BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator pass... |
| CVE-2004-2319 | — | — | 0.5% | Dec 31, 2004 | IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log f... |
| CVE-2004-2318 | — | — | 1.9% | Dec 31, 2004 | The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a... |
| CVE-2004-2600 | — | — | 2.6% | Dec 31, 2004 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped... |
| CVE-2004-2316 | — | — | 1.7% | Dec 31, 2004 | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request ... |
| CVE-2004-2315 | — | — | 1.7% | Dec 31, 2004 | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIO... |
| CVE-2004-2314 | — | — | 2.4% | Dec 31, 2004 | The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, whic... |
| CVE-2004-2313 | — | — | 1.4% | Dec 31, 2004 | Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords... |
| CVE-2004-2375 | — | — | 5.9% | Dec 31, 2004 | Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (cr... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now