2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2075Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is no...
CVE-2004-2074Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string ...
CVE-2004-2456SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL com...
CVE-2004-2072Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows r...
CVE-2004-2071Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat...
CVE-2004-2069sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly si...
CVE-2004-2068fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empt...
CVE-2004-2453Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown im...
CVE-2004-2640Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files...
CVE-2004-2115Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker...
CVE-2004-2065DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension ...
CVE-2004-2063Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inje...
CVE-2004-2062SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary...
CVE-2004-2060ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the...
CVE-2004-2059Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or ...
CVE-2004-2058ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
CVE-2004-2057SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
CVE-2004-2056SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statement...
CVE-2004-2448S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, w...
CVE-2004-2054CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks...
CVE-2004-2447Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s...
CVE-2004-2052eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual passwor...
CVE-2004-2446Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a "....
CVE-2004-2050eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-S...
CVE-2004-2476Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now