2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2605aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Ge...
CVE-2004-2385EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for ...
CVE-2004-2386Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote att...
CVE-2004-2606The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to...
CVE-2004-2715edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by ...
CVE-2004-2716Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQ...
CVE-2004-2387Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attac...
CVE-2004-2388rexecd for AIX 4.3.3 does not properly use a local copy of the pwd structure when calling getpwnam, which may cause the ...
CVE-2004-2607A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users...
CVE-2004-2389Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attack...
CVE-2004-2390The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when usin...
CVE-2004-2608SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insuffi...
CVE-2004-2717Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrativ...
CVE-2004-2391Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of ...
CVE-2004-2392libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, rel...
CVE-2004-2609The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive inf...
CVE-2004-2393Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client o...
CVE-2004-2394Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters...
CVE-2004-2610mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount optio...
CVE-2004-2718PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive in...
CVE-2004-2395Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of fa...
CVE-2004-2396passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that ...
CVE-2004-2611The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophst...
CVE-2004-2398Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local user...
CVE-2004-2399Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumptio...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now