2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2075 | — | — | 1.8% | Dec 31, 2004 | Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is no... |
| CVE-2004-2074 | — | — | 35.8% | Dec 31, 2004 | Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string ... |
| CVE-2004-2456 | — | — | 2.6% | Dec 31, 2004 | SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL com... |
| CVE-2004-2072 | — | — | 4.2% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows r... |
| CVE-2004-2071 | — | — | 3.5% | Dec 31, 2004 | Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat... |
| CVE-2004-2069 | — | — | 3.4% | Dec 31, 2004 | sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly si... |
| CVE-2004-2068 | — | — | 1.6% | Dec 31, 2004 | fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empt... |
| CVE-2004-2453 | — | — | 1.7% | Dec 31, 2004 | Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown im... |
| CVE-2004-2640 | — | — | 8.1% | Dec 31, 2004 | Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files... |
| CVE-2004-2115 | — | — | 58.4% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker... |
| CVE-2004-2065 | — | — | 1.9% | Dec 31, 2004 | DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension ... |
| CVE-2004-2063 | — | — | 3.6% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inje... |
| CVE-2004-2062 | — | — | 2.4% | Dec 31, 2004 | SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary... |
| CVE-2004-2060 | — | — | 7.9% | Dec 31, 2004 | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the... |
| CVE-2004-2059 | — | — | 8.8% | Dec 31, 2004 | Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or ... |
| CVE-2004-2058 | — | — | 1.8% | Dec 31, 2004 | ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages. |
| CVE-2004-2057 | — | — | 1.5% | Dec 31, 2004 | SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements. |
| CVE-2004-2056 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statement... |
| CVE-2004-2448 | — | — | 1.4% | Dec 31, 2004 | S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, w... |
| CVE-2004-2054 | — | — | 2.2% | Dec 31, 2004 | CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks... |
| CVE-2004-2447 | — | — | 2.7% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s... |
| CVE-2004-2052 | — | — | 1.1% | Dec 31, 2004 | eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual passwor... |
| CVE-2004-2446 | — | — | 2.0% | Dec 31, 2004 | Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".... |
| CVE-2004-2050 | — | — | 0.4% | Dec 31, 2004 | eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-S... |
| CVE-2004-2476 | — | — | 9.1% | Dec 31, 2004 | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now