2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2418 | — | — | 1.4% | Dec 31, 2004 | Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1... |
| CVE-2004-2722 | — | — | 0.3% | Dec 31, 2004 | Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. ... |
| CVE-2004-2417 | — | — | 2.7% | Dec 31, 2004 | Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code... |
| CVE-2004-2620 | — | — | 0.9% | Dec 31, 2004 | The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers... |
| CVE-2004-2416 | — | — | 60.6% | Dec 31, 2004 | Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GE... |
| CVE-2004-1836 | — | — | 4.4% | Dec 31, 2004 | SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to... |
| CVE-2004-2115 | — | — | 58.4% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker... |
| CVE-2004-2415 | — | — | 1.5% | Dec 31, 2004 | Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML fi... |
| CVE-2004-2414 | — | — | 0.4% | Dec 31, 2004 | Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with ... |
| CVE-2004-1887 | — | — | 3.8% | Dec 31, 2004 | Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t... |
| CVE-2004-2413 | — | — | 1.2% | Dec 31, 2004 | SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL com... |
| CVE-2004-2618 | — | — | 2.2% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary we... |
| CVE-2004-2412 | — | — | 1.2% | Dec 31, 2004 | Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitra... |
| CVE-2004-1883 | — | — | 5.2% | Dec 31, 2004 | Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code... |
| CVE-2004-2116 | — | — | 8.7% | Dec 31, 2004 | Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .... |
| CVE-2004-2411 | — | — | 2.2% | Dec 31, 2004 | The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs... |
| CVE-2004-2410 | — | — | 0.4% | Dec 31, 2004 | Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of ser... |
| CVE-2004-2721 | — | — | 1.7% | Dec 31, 2004 | The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the "p" variable might not be pr... |
| CVE-2004-2409 | — | — | 0.5% | Dec 31, 2004 | Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t updat... |
| CVE-2004-2616 | — | — | 1.2% | Dec 31, 2004 | The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information... |
| CVE-2004-2408 | — | — | 0.4% | Dec 31, 2004 | Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and... |
| CVE-2004-1937 | — | — | 8.1% | Dec 31, 2004 | Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbit... |
| CVE-2004-2407 | — | — | 1.5% | Dec 31, 2004 | Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security ho... |
| CVE-2004-2615 | — | — | 0.3% | Dec 31, 2004 | The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manual... |
| CVE-2004-2476 | — | — | 9.1% | Dec 31, 2004 | Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now