2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2685——Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre...
CVE-2004-2686——Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load ar...
CVE-2004-2687——distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at...
CVE-2004-2688——Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script ...
CVE-2004-2689——NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; ...
CVE-2004-2690——Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrator...
CVE-2004-2691——Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers t...
CVE-2004-2692——The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass rest...
CVE-2004-2693——HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allow...
CVE-2004-2694——Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrar...
CVE-2004-2695——SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 th...
CVE-2004-2696——BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inte...
CVE-2004-2697——The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via...
CVE-2004-2698——Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial ...
CVE-2004-2699——deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified Pro...
CVE-2004-2700——Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload a...
CVE-2004-2701——Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject ar...
CVE-2004-2702——Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to injec...
CVE-2004-2703——Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Su...
CVE-2004-2704——Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the C...
CVE-2004-2705——Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain att...
CVE-2004-2706——Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service ...
CVE-2004-2707——Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors rel...
CVE-2004-2708——Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by ...
CVE-2004-2709——Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now