2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-0358 | — | — | 4.2% | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrar... |
| CVE-2004-0357 | — | — | 5.0% | Nov 23, 2004 | Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2)... |
| CVE-2004-0356 | — | — | 7.5% | Nov 23, 2004 | Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to exec... |
| CVE-2004-0355 | — | — | 1.7% | Nov 23, 2004 | Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal P... |
| CVE-2004-0354 | — | — | 15.6% | Nov 23, 2004 | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to ex... |
| CVE-2004-0353 | — | — | 4.7% | Nov 23, 2004 | Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow... |
| CVE-2004-0352 | — | — | 3.2% | Nov 23, 2004 | Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02... |
| CVE-2004-0351 | — | — | 0.5% | Nov 23, 2004 | Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local u... |
| CVE-2004-0350 | — | — | 0.5% | Nov 23, 2004 | SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local user... |
| CVE-2004-0349 | — | — | 3.2% | Nov 23, 2004 | Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot ... |
| CVE-2004-0348 | — | — | 3.3% | Nov 23, 2004 | SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arb... |
| CVE-2004-0347 | — | — | 2.1% | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (bu... |
| CVE-2004-0346 | HIGH | 7.8 | 5.7% | Nov 23, 2004 | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privile... |
| CVE-2004-0345 | — | — | 6.0% | Nov 23, 2004 | Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server... |
| CVE-2004-0344 | — | — | 2.2% | Nov 23, 2004 | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete... |
| CVE-2004-0343 | — | — | 1.8% | Nov 23, 2004 | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL v... |
| CVE-2004-0342 | MEDIUM | 5.5 | 0.4% | Nov 23, 2004 | WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service ... |
| CVE-2004-0341 | — | — | 0.4% | Nov 23, 2004 | WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local us... |
| CVE-2004-0340 | — | — | 1.3% | Nov 23, 2004 | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Se... |
| CVE-2004-0339 | — | — | 1.4% | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers... |
| CVE-2004-0338 | — | — | 2.4% | Nov 23, 2004 | SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL quer... |
| CVE-2004-0337 | — | — | 2.0% | Nov 23, 2004 | Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary scrip... |
| CVE-2004-0336 | — | — | 1.5% | Nov 23, 2004 | LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains ... |
| CVE-2004-0335 | — | — | 1.4% | Nov 23, 2004 | LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a ... |
| CVE-2004-0334 | — | — | 1.7% | Nov 23, 2004 | InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_adminde... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now