2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1837Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remot...
CVE-2004-2406Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
CVE-2004-2615The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manual...
CVE-2004-1966Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execu...
CVE-2004-2405Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote ...
CVE-2004-2650Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by trigger...
CVE-2004-2403Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized ...
CVE-2004-1962SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filt...
CVE-2004-2402Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary ...
CVE-2004-1960Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inje...
CVE-2004-2401Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute ...
CVE-2004-1958Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files ...
CVE-2004-2400WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local us...
CVE-2004-2113Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or ...
CVE-2004-1955SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via...
CVE-2004-2398Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local user...
CVE-2004-1953phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which re...
CVE-2004-2396passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that ...
CVE-2004-1951xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite a...
CVE-2004-2395Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of fa...
CVE-2004-1949SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the s...
CVE-2004-2115Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker...
CVE-2004-2394Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters...
CVE-2004-2393Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client o...
CVE-2004-2476Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now