2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-2760——sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attemp...
CVE-2004-9998——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate has been used as a placeho...
CVE-2004-1376——Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers ...
CVE-2004-1316——Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote at...
CVE-2004-1062——Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and...
CVE-2004-1317——Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack...
CVE-2004-1377——The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwri...
CVE-2004-0834——Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) m...
CVE-2004-0833——Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fi...
CVE-2004-0816HIGH7.5Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a de...
CVE-2004-0814——Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain p...
CVE-2004-0810——Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) vi...
CVE-2004-0805——Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code ...
CVE-2004-0803——Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer over...
CVE-2004-0749——The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable...
CVE-2004-1373——Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) ...
CVE-2004-0564——Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local user...
CVE-2004-0601——distcc before 2.16, when running on 64-bit platforms, does not interpret IP-based access control rules correctly, which ...
CVE-2004-0563——The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions,...
CVE-2004-1375——Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows loca...
CVE-2004-0512——Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow ...
CVE-2004-0850——Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow l...
CVE-2004-0849——Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2....
CVE-2004-0842——Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service...
CVE-2004-0841——Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.sho...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now