2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1814Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. ...
CVE-2004-1813VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trai...
CVE-2004-1812Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 a...
CVE-2004-1811The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote...
CVE-2004-1810The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array...
CVE-2004-1809Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web scr...
CVE-2004-1808Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbit...
CVE-2004-1807Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web ...
CVE-2004-1806SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) c...
CVE-2004-1805Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of...
CVE-2004-1804wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HT...
CVE-2004-1802Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which ...
CVE-2004-1801Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot)...
CVE-2004-1800Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access v...
CVE-2004-1799PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original...
CVE-2004-2115Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker...
CVE-2004-1797Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to i...
CVE-2004-1796PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co...
CVE-2004-1795Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
CVE-2004-1794Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script o...
CVE-2004-1793Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execu...
CVE-2004-1792swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via ...
CVE-2004-1791The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also a...
CVE-2004-2476Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF...
CVE-2004-2116Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a ....

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now