2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-1053Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certa...
CVE-2004-1038A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sens...
CVE-2004-1035Multiple integer signedness errors in (1) imapcommon.c, (2) main.c, (3) request.c, and (4) select.c for up-imapproxy IMA...
CVE-2004-1036Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail...
CVE-2004-1051sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create...
CVE-2004-1037The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in ...
CVE-2004-1055Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject...
CVE-2004-1031fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and lo...
CVE-2004-1029The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, do...
CVE-2004-1030fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by cal...
CVE-2004-1032fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create ...
CVE-2004-1010Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote at...
CVE-2004-1021iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use...
CVE-2004-1027Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite ...
CVE-2004-1033Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypas...
CVE-2004-1006Format string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary co...
CVE-2004-1007The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (applic...
CVE-2004-1003Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability ...
CVE-2004-1034Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows ...
CVE-2004-0945The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authe...
CVE-2004-0481The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local ...
CVE-2004-0966The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secu...
CVE-2004-0965stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allow...
CVE-2004-0967The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Se...
CVE-2004-0963Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now