2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-1518 | — | — | 2.3% | Dec 31, 2004 | SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbi... |
| CVE-2004-1515 | — | — | 1.0% | Dec 31, 2004 | SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute a... |
| CVE-2004-1516 | — | — | 1.6% | Dec 31, 2004 | CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitti... |
| CVE-2004-1398 | — | — | 0.4% | Dec 31, 2004 | Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and p... |
| CVE-2004-1200 | — | — | 2.2% | Dec 31, 2004 | Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as ... |
| CVE-2004-1519 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands ... |
| CVE-2004-1400 | — | — | 7.2% | Dec 31, 2004 | The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unaut... |
| CVE-2004-1520 | — | — | 88.5% | Dec 31, 2004 | Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon... |
| CVE-2004-1512 | — | — | 1.4% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute... |
| CVE-2004-1513 | — | — | 1.7% | Dec 31, 2004 | 04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inj... |
| CVE-2004-1198 | — | — | 1.7% | Dec 31, 2004 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumpt... |
| CVE-2004-1389 | — | — | 9.9% | Dec 31, 2004 | Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1... |
| CVE-2004-1514 | — | — | 1.8% | Dec 31, 2004 | 04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for... |
| CVE-2004-1811 | — | — | 2.3% | Dec 31, 2004 | The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote... |
| CVE-2004-1812 | — | — | 46.2% | Dec 31, 2004 | Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 a... |
| CVE-2004-1508 | — | — | 1.6% | Dec 31, 2004 | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. |
| CVE-2004-1521 | — | — | 1.7% | Dec 31, 2004 | Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable... |
| CVE-2004-1509 | — | — | 1.6% | Dec 31, 2004 | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter... |
| CVE-2004-0948 | — | — | — | Dec 31, 2004 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2004-1510 | — | — | 1.8% | Dec 31, 2004 | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upc... |
| CVE-2004-1570 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p... |
| CVE-2004-1397 | — | — | 1.3% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2004-1437 | — | — | 13.4% | Dec 31, 2004 | Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attacke... |
| CVE-2004-0908 | — | — | 2.5% | Dec 31, 2004 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript... |
| CVE-2004-1017 | — | — | 3.3% | Dec 31, 2004 | Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors. |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now