2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0349——Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot ...
CVE-2004-0350——SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local user...
CVE-2004-0351——Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local u...
CVE-2004-0494——Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform ce...
CVE-2004-0352——Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02...
CVE-2004-0353——Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow...
CVE-2004-0354——Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to ex...
CVE-2004-0355——Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal P...
CVE-2004-0356——Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to exec...
CVE-2004-1331——The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Sec...
CVE-2004-1315——viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase...
CVE-2004-0815——The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down ...
CVE-2004-0552——Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device na...
CVE-2004-0569——The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of ...
CVE-2004-0572——Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary cod...
CVE-2004-0574——The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser...
CVE-2004-0575——Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows S...
CVE-2004-0774——RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of s...
CVE-2004-0804——Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via ...
CVE-2004-0828——The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before execu...
CVE-2004-0832——The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled...
CVE-2004-0835——MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o...
CVE-2004-0836——Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS...
CVE-2004-0837——MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multi...
CVE-2004-0840——The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows ...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now