2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-2509 | — | — | 2.2% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads... |
| CVE-2004-2510 | — | — | 3.9% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to in... |
| CVE-2004-2511 | — | — | 5.3% | Dec 31, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb... |
| CVE-2004-2512 | — | — | 4.6% | Dec 31, 2004 | CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP res... |
| CVE-2004-2513 | — | — | 9.8% | Dec 31, 2004 | Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via... |
| CVE-2004-2514 | — | — | 1.9% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attacker... |
| CVE-2004-2515 | — | — | 0.5% | Dec 31, 2004 | Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow loc... |
| CVE-2004-2516 | — | — | 8.4% | Dec 31, 2004 | Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET ... |
| CVE-2004-2517 | — | — | 3.6% | Dec 31, 2004 | myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon... |
| CVE-2004-2518 | — | — | 4.5% | Dec 31, 2004 | Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"... |
| CVE-2004-2519 | — | — | 8.0% | Dec 31, 2004 | Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif... |
| CVE-2004-2520 | — | — | 3.3% | Dec 31, 2004 | POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio... |
| CVE-2004-2521 | — | — | 1.8% | Dec 31, 2004 | Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) v... |
| CVE-2004-2522 | — | — | 4.0% | Dec 31, 2004 | Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a... |
| CVE-2004-2523 | — | — | 5.4% | Dec 31, 2004 | Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem... |
| CVE-2004-2524 | — | — | 1.7% | Dec 31, 2004 | clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username an... |
| CVE-2004-2526 | — | — | 9.3% | Dec 31, 2004 | Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t... |
| CVE-2004-0592 | — | — | 2.4% | Dec 31, 2004 | The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when... |
| CVE-2004-0638 | — | — | 6.6% | Dec 31, 2004 | Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Re... |
| CVE-2004-0780 | — | — | 0.5% | Dec 31, 2004 | Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line... |
| CVE-2004-0789 | — | — | 2.8% | Dec 31, 2004 | Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Netw... |
| CVE-2004-0802 | — | — | 3.4% | Dec 31, 2004 | Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a special... |
| CVE-2004-0806 | — | — | 1.7% | Dec 31, 2004 | cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu... |
| CVE-2004-0808 | — | — | 5.4% | Dec 31, 2004 | The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows... |
| CVE-2004-0811 | — | — | 6.8% | Dec 31, 2004 | Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to o... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now