2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0923CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local us...
CVE-2004-0917The default installation of Vignette Application Portal installs the diagnostic utility without authentication requireme...
CVE-2004-0888Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphic...
CVE-2004-0927ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows...
CVE-2004-0933Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and ...
CVE-2004-0926Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbi...
CVE-2004-0935Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compress...
CVE-2004-0925Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authent...
CVE-2004-0932McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004...
CVE-2004-1340Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, whi...
CVE-2004-1057Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorr...
CVE-2004-1184The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell m...
CVE-2004-1185Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands v...
CVE-2004-1039The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd,...
CVE-2004-0897The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which ...
CVE-2004-0991Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or ...
CVE-2004-1135Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service ...
CVE-2004-1134Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possib...
CVE-2004-1136Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of...
CVE-2004-1133Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to injec...
CVE-2004-1147phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to...
CVE-2004-1138VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted model...
CVE-2004-1148phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files v...
CVE-2004-1137Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local an...
CVE-2004-1130Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary we...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now