2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1461——Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random...
CVE-2004-1842HIGH8.8Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administra...
CVE-2004-1413——Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands v...
CVE-2004-1456——filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
CVE-2004-1401——SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and b...
CVE-2004-1459——Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIU...
CVE-2004-1411——Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that ...
CVE-2004-1402——SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string pa...
CVE-2004-1583——Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write...
CVE-2004-1592——PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute ar...
CVE-2004-1845——Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary ...
CVE-2004-0802——Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a special...
CVE-2004-1429——ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it e...
CVE-2004-1453——GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use...
CVE-2004-1431——FormMail.php 5.0, and possibly other versions, allows remote attackers to read arbitrary files via a full pathname in th...
CVE-2004-0806——cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu...
CVE-2004-1454——Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial...
CVE-2004-0567——The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Ser...
CVE-2004-1414——Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that conta...
CVE-2004-1415——SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote att...
CVE-2004-1455——Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrar...
CVE-2004-1460——Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory ...
CVE-2004-1755——The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple c...
CVE-2004-1848——Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file siz...
CVE-2004-1449——Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of ...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now