2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2627Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Vi...
CVE-2004-2726HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which a...
CVE-2004-2429Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to ex...
CVE-2004-2430Trend OfficeScan Corporate Edition 5.58 and possibly earler does not drop privileges when opening a help window from a v...
CVE-2004-2628Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to...
CVE-2004-2431Unknown vulnerability in The Ignition Project ignitionServer 0.1.2 through 0.3.1, with the linking service enabled, allo...
CVE-2004-2432WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a l...
CVE-2004-2629Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (wh...
CVE-2004-2727Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a deni...
CVE-2004-2433Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, ...
CVE-2004-2434Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with...
CVE-2004-2630The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows...
CVE-2004-2435Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" ...
CVE-2004-2436Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndA...
CVE-2004-2631Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote at...
CVE-2004-2728Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a ...
CVE-2004-2676The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when u...
CVE-2004-1479Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0928. Reason: This candidate is a duplicate of...
CVE-2004-2175Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands vi...
CVE-2004-2171Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script...
CVE-2004-2437SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstar...
CVE-2004-2438Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HT...
CVE-2004-2632phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to My...
CVE-2004-2439The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote att...
CVE-2004-2440Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now