2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2419Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on ...
CVE-2004-2723NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
CVE-2004-2418Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1...
CVE-2004-2621Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway cer...
CVE-2004-2417Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code...
CVE-2004-1837Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remot...
CVE-2004-2113Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or ...
CVE-2004-2416Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GE...
CVE-2004-2415Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML fi...
CVE-2004-1879Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script ...
CVE-2004-2414Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with ...
CVE-2004-2619ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment con...
CVE-2004-2413SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL com...
CVE-2004-1887Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t...
CVE-2004-2115Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker...
CVE-2004-2412Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitra...
CVE-2004-2411The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs...
CVE-2004-2722Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. ...
CVE-2004-2410Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of ser...
CVE-2004-2617Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the ...
CVE-2004-2409Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t updat...
CVE-2004-1889Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (ha...
CVE-2004-2408Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and...
CVE-2004-2616The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information...
CVE-2004-2476Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now