2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1501The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CP...
CVE-2004-2189SQL injection vulnerability in DMXReady Site Chassis Manager allows remote attackers to execute arbitrary SQL commands v...
CVE-2004-1914SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execut...
CVE-2004-1460Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory ...
CVE-2004-1937Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbit...
CVE-2004-0567The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Ser...
CVE-2004-1824Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web...
CVE-2004-1848Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file siz...
CVE-2004-1940sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN respon...
CVE-2004-1958Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files ...
CVE-2004-2205Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified...
CVE-2004-2253Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary fi...
CVE-2004-1910rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to ...
CVE-2004-1911Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script ...
CVE-2004-0561Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a deni...
CVE-2004-0560Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly exec...
CVE-2004-1912The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen...
CVE-2004-1410Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary ...
CVE-2004-1411Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that ...
CVE-2004-1508init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
CVE-2004-1426Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitr...
CVE-2004-1507CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return...
CVE-2004-1414Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that conta...
CVE-2004-1882Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbit...
CVE-2004-2225Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted ...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now