2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2612BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functional...
CVE-2004-2400WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local us...
CVE-2004-2401Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute ...
CVE-2004-2613Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer ...
CVE-2004-2402Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary ...
CVE-2004-2403Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized ...
CVE-2004-2614Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary...
CVE-2004-2719Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrar...
CVE-2004-2720Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers...
CVE-2004-2232SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to mod...
CVE-2004-2405Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote ...
CVE-2004-2406Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
CVE-2004-2615The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manual...
CVE-2004-2407Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security ho...
CVE-2004-2408Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and...
CVE-2004-2616The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information...
CVE-2004-2721The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the "p" variable might not be pr...
CVE-2004-2409Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t updat...
CVE-2004-2410Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of ser...
CVE-2004-2617Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the ...
CVE-2004-2411The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs...
CVE-2004-2412Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitra...
CVE-2004-2618Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary we...
CVE-2004-2722Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. ...
CVE-2004-2413SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL com...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now