2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2610——mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount optio...
CVE-2004-2611——The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophst...
CVE-2004-2612——BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functional...
CVE-2004-2613——Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer ...
CVE-2004-2614——Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary...
CVE-2004-2615——The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manual...
CVE-2004-2616——The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information...
CVE-2004-2617——Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the ...
CVE-2004-2618——Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary we...
CVE-2004-2619——ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment con...
CVE-2004-2620——The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers...
CVE-2004-2621——Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway cer...
CVE-2004-2622——AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server ...
CVE-2004-2623——Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors ...
CVE-2004-2624——Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary we...
CVE-2004-2625——Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTM...
CVE-2004-2626——GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SM...
CVE-2004-2627——Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Vi...
CVE-2004-2628——Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to...
CVE-2004-2629——Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (wh...
CVE-2004-2630——The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows...
CVE-2004-2631——Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote at...
CVE-2004-2632——phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to My...
CVE-2004-2633——Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users...
CVE-2004-2634——The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now