2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-2509——Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads...
CVE-2004-2510——Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to in...
CVE-2004-2511——Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb...
CVE-2004-2512——CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP res...
CVE-2004-2513——Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via...
CVE-2004-2514——Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attacker...
CVE-2004-2515——Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow loc...
CVE-2004-2516——Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET ...
CVE-2004-2517——myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon...
CVE-2004-2518——Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"...
CVE-2004-2519——Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif...
CVE-2004-2520——POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio...
CVE-2004-2521——Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) v...
CVE-2004-2522——Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a...
CVE-2004-2523——Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem...
CVE-2004-2524——clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username an...
CVE-2004-2526——Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t...
CVE-2004-0592——The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when...
CVE-2004-0638——Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Re...
CVE-2004-0780——Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line...
CVE-2004-0789——Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Netw...
CVE-2004-0802——Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a special...
CVE-2004-0806——cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu...
CVE-2004-0808——The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows...
CVE-2004-0811——Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to o...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now